Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Airflow — Vulnerabilities & Security Advisories 146

All 146 CVE vulnerabilities found in Apache Airflow, with AI-generated Chinese analysis, references, and POCs.

This page documents security weaknesses associated with the Apache Airflow workflow orchestration tool, categorized under common vulnerability types and industry-standard tags. It aggregates a comprehensive collection of identified security flaws, including those related to authentication bypass, insecure configuration, and remote code execution risks. The data spans from the initial public release of the software through the most recent updates, ensuring a historical perspective on the product's security posture over time. Visitors to this page can effectively track vendor advisories and official patch releases to stay informed about critical fixes as they are issued. Additionally, users can gain a deeper understanding of specific weakness classes affecting the platform, analyzing how particular defect categories manifest within its architecture. The resource also allows for a detailed lookup of the product’s vulnerability history, enabling security professionals to review past incidents and assess the evolution of risk over various versions. This structured approach supports informed decision-making for system administrators and DevOps engineers responsible for maintaining secure deployment environments. By consolidating these data points, the page serves as a central reference for evaluating the ongoing security health of Apache Airflow installations. It facilitates proactive risk management by highlighting trends and recurring issues that may require immediate attention or mitigation strategies. The information provided is intended solely for technical assessment and does not constitute professional security advice. Users are encouraged to cross-reference this data with official documentation and community reports for the most accurate and timely guidance.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-45426 Apache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access CWE-863 - - 2026-06-01
CVE-2026-46764 Apache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permission filter CWE-639 - - 2026-06-01
CVE-2026-48726 Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path CWE-613 - - 2026-06-01
CVE-2026-49298 Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments CWE-538 - - 2026-06-01
CVE-2026-45192 Apache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API Response CWE-200 - - 2026-06-01
CVE-2026-38743 Apache Airflow: Dags endpoint might provide access to otherwise inaccessible entities CWE-1220 4.3AI Medium AI 2026-04-24
CVE-2026-40690 Apache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users CWE-1220 4.3AI Medium AI 2026-04-24
CVE-2026-32690 Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1 CWE-668 7.5AI High AI 2026-04-18
CVE-2026-30898 Apache Airflow: Bad example of BashOperator shell injection via dag_run.conf CWE-77 8.8AI High AI 2026-04-18
CVE-2026-30912 Apache Airflow: Exposing stack trace in case of constraint error CWE-668 7.5AI High AI 2026-04-18
CVE-2026-25917 Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5) CWE-502 9.8AI Critical AI 2026-04-18
CVE-2026-32228 Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to CWE-863 7.1AI High AI 2026-04-18
CVE-2026-31987 Apache Airflow: JWT token appearing in logs CWE-532 6.5AI Medium AI 2026-04-16
CVE-2026-25219 Apache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access CWE-200 6.5 - 2026-04-15
CVE-2025-54550 Apache Airflow: RCE by race condition in example_xcom dag CWE-94 8.8 - 2026-04-15
CVE-2026-33858 Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API CWE-502 9.8 - 2026-04-13
CVE-2025-66236 Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI CWE-532 9.6 - 2026-04-13
CVE-2025-57735 Apache Airflow: Airflow Logout Not Invalidating JWT CWE-613 9.1AI Critical AI 2026-04-09
CVE-2026-34538 Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure) CWE-668 6.5AI Medium AI 2026-04-09
CVE-2026-28563 Apache Airflow: DAG authorization bypass CWE-732 4.3 - 2026-03-17
CVE-2026-26929 Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata CWE-732 5.3AI Medium AI 2026-03-17
CVE-2026-30911 Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization CWE-862 8.1AI High AI 2026-03-17
CVE-2026-28779 Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications CWE-668 9.8AI Critical AI 2026-03-17
CVE-2025-27555 Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli CWE-532 6.5AI Medium AI 2026-02-24
CVE-2024-56373 Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information CWE-94 8.0AI High AI 2026-02-24
CVE-2025-65995 Apache Airflow: Disclosure of secrets to UI via kwargs CWE-209 6.5AI Medium AI 2026-02-21
CVE-2026-22922 Apache Airflow: Airflow externalLogUrl Permission Bypass CWE-648 4.3AI Medium AI 2026-02-09
CVE-2026-24098 Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors CWE-200 4.3AI Medium AI 2026-02-09
CVE-2025-68675 Apache Airflow: proxy credentials for various providers might leak in task logs CWE-532 7.5 - 2026-01-16
CVE-2025-68438 Apache Airflow: Secrets in rendered templates could contain parts of sensitive values when truncated CWE-200 7.5 - 2026-01-16

All 146 known CVE vulnerabilities affecting Apache Airflow with full Chinese analysis, references, and POCs where available.