Where
-Infinity
0

pypi/apache-airflowApache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API Response

Risk 40
Severity
6.5
First published (updated )

pypi/apache-airflowApache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permission filter

Risk 24
Severity
4.3
First published (updated )

pypi/apache-airflowApache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access

Risk 18
Severity
3.1
First published (updated )

pypi/apache-airflowApache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator

Risk 83
Severity
8.8
First published (updated )

oss-secCVE-2026-49298: Apache Airflow: JWT Token Exposuin KubernetesExecutor Command-Line Arguments

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-secCVE-2026-45426: Apache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access

oss-secCVE-2026-45360: Apache Airflow: Arbitrary import in custom deadline-fence deserialization

oss-secCVE-2026-42252: Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user pattern

pypi/apache-airflowApache Airflow: DAG authorization bypass on /ui/structure/structure_data

Risk 18
Severity
3.1
First published (updated )

oss-secCVE-2026-41084: Apache Airflow: API authorization bypass: bulk TaskInstances allows cross-DAG mutation

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pypi/apache-airflowApache Airflow: Arbitrary File Read via Log Symlink following in FileTaskHandler

Risk 40
Severity
6.5
First published (updated )

oss-secCVE-2026-41014: Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints

oss-secCVE-2026-40963: Apache Airflow: DAG authorization bypass on /ui/structu/structu_data

oss-secCVE-2026-40961: Apache Airflow: Open dict Bypass Vulnerability

oss-secCVE-2026-30912: Apache Airflow: Exposing stack trace in case of constraint error

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-secCVE-2026-31987: Apache Airflow: JWT token appearing in logs

oss-secCVE-2025-54550: Apache Airflow: RCE by race condition in example_xcom dag

oss-secCVE-2025-66236: Apache Airflow: Sects from Airflow config file logged in plain text in DAG run logs UI

pypi/apache-airflowApache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli

Risk 40
Severity
6.5
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203