https://seclists.org/oss-sec/2026/q3/77: CVE-2026-48891: Apache Airflow: /ui/dependencies scheduling graph leaks unadable Dag identifiers via trigger/sensor dep.source/dep.target
Published Jul 7, 2026
·Updated
Affected Software
1 affected component
Apache Airflow<3.3.0
Frequently Asked Questions
1
What is the severity of CVE-2026-48891?
The severity of CVE-2026-48891 is classified as low.
2
Which versions of Apache Airflow are affected by CVE-2026-48891?
CVE-2026-48891 affects Apache Airflow versions before 3.3.0.
3
What does CVE-2026-48891 exploit?
CVE-2026-48891 exploits a bug in the `/ui/dependencies` scheduling graph endpoint that leaks unreadable Dag identifiers.
4
How do I fix CVE-2026-48891?
To fix CVE-2026-48891, upgrade to Apache Airflow version 3.3.0 or later.
5
What impact does CVE-2026-48891 have on data confidentiality?
CVE-2026-48891 can lead to exposure of Dag identifiers that may compromise the confidentiality of scheduling workflows.