VYPR

Airflow

by Apache

pypi: airflow

Source repositories

CVEs (187)

  • CVE-2023-46288MedOct 23, 2023
    risk 0.21cvss 4.3epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.4.0 to 2.7.0. Sensitive configuration information has been exposed to authenticated users with the ability to read configuration via Airflow REST…

  • CVE-2023-45348MedOct 14, 2023
    risk 0.21cvss 4.3epss 0.01

    Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default. It is…

  • CVE-2023-40611MedSep 12, 2023
    risk 0.21cvss 4.3epss 0.02

    Apache Airflow, versions before 2.7.1, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users…

  • CVE-2026-82355MedSep 21, 2026
    risk 0.20cvss 4.2epss 0.01

    When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over cookie. The request then executes -- and…

  • CVE-2026-32690LowApr 18, 2026
    risk 0.17cvss 3.7epss 0.01

    Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise…

  • CVE-2026-45426LowJun 1, 2026
    risk 0.13cvss 3.1epss 0.01

    Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log server authorized JWT tokens against Dag IDs by applying Python's `str.lstrip()` to the requested path segment when…

  • CVE-2026-40963LowJun 1, 2026
    risk 0.13cvss 3.1epss 0.01

    The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags. An authenticated UI/API user authorized for one Dag could enumerate linked Dag IDs and dependency…

Page 10 of 10