VYPR

Airflow

by Apache

pypi: airflow

Source repositories

CVEs (187)

  • CVE-2017-17835HigJan 23, 2019
    risk 0.50cvss 8.8epss 0.02

    In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.

  • CVE-2017-15720HigJan 23, 2019
    risk 0.50cvss 8.8epss 0.03

    In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.

  • CVE-2026-68968HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.01

    Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts…

  • CVE-2026-67260HigAug 12, 2026
    risk 0.48cvss 7.3epss 0.01

    Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task…

  • CVE-2024-56373HigFeb 24, 2026
    risk 0.48cvss 8.4epss 0.01

    DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which they should normally not be able to do, leading to potentially remote code execution in the context of web-server…

  • CVE-2026-86466HigSep 16, 2026
    risk 0.46cvss 8.1epss 0.00

    Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different client application can present…

  • CVE-2026-49297HigJul 6, 2026
    risk 0.46cvss 8.1epss 0.01

    Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the…

  • CVE-2026-45361HigMay 25, 2026
    risk 0.46cvss 8.1epss 0.01

    Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to…

  • CVE-2025-54550HigApr 15, 2026
    risk 0.46cvss 8.1epss 0.01

    The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to allow UI user who had access to modify XComs to perform arbitrary execution of code on the worker. Since the UI users…

  • CVE-2026-30911HigMar 17, 2026
    risk 0.46cvss 8.1epss 0.01

    Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instance. Users are…

  • CVE-2024-28746HigMar 14, 2024
    risk 0.46cvss 8.1epss 0.01

    Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.  Users of Apache Airflow are…

  • CVE-2023-37379HigAug 23, 2023
    risk 0.46cvss 8.1epss 0.02

    Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exploit the test connection feature by…

  • CVE-2022-41672HigOct 7, 2022
    risk 0.46cvss 8.1epss 0.01

    In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API.

  • CVE-2023-40273HigAug 23, 2023
    risk 0.45cvss 8.0epss 0.02

    The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the session of the user. Other than manually cleaning the session database (for…

  • CVE-2020-17526HigDec 21, 2020
    risk 0.45cvss 7.7epss 0.23

    Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. This does not affect…

  • CVE-2022-41131HigNov 22, 2022
    risk 0.44cvss 7.8epss 0.02

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG files. This issue…

  • CVE-2026-75157HigSep 18, 2026
    risk 0.42cvss 7.5epss 0.00

    Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently suppressing asset-triggered scheduling for it…

  • CVE-2026-65017MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.01

    Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with no prior access to…

  • CVE-2026-59244MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.00

    Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in…

  • CVE-2026-49486HigJun 26, 2026
    risk 0.42cvss 7.5epss 0.00

    The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or…

Page 3 of 10