VYPR

Airflow

by Apache

pypi: airflow

Source repositories

CVEs (187)

  • CVE-2022-45402MedNov 15, 2022
    risk 0.39cvss 6.1epss 0.82

    In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.

  • CVE-2026-97636MedSep 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to…

  • CVE-2026-86465MedSep 16, 2026
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a…

  • CVE-2026-68971MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manager distinguishes a…

  • CVE-2026-68970MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list…

  • CVE-2026-68969MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.01

    Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and…

  • CVE-2026-59242MedAug 12, 2026
    risk 0.35cvss 5.4epss 0.01

    Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to…

  • CVE-2026-68868MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.01

    The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved…

  • CVE-2026-68872MedAug 10, 2026
    risk 0.35cvss 6.5epss 0.01

    The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either…

  • CVE-2026-68871MedAug 10, 2026
    risk 0.35cvss 6.5epss 0.01

    The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could…

  • CVE-2026-49487MedJul 7, 2026
    risk 0.35cvss 6.5epss 0.01

    In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, any authenticated user with DAG-scoped…

  • CVE-2026-49296MedJul 7, 2026
    risk 0.35cvss 6.5epss 0.01

    Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire source file without redacting…

  • CVE-2026-48892MedJul 7, 2026
    risk 0.35cvss 6.5epss 0.01

    The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option names were not in…

  • CVE-2026-48828MedJul 7, 2026
    risk 0.35cvss 6.5epss 0.01

    The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable…

  • CVE-2026-49818MedJun 9, 2026
    risk 0.35cvss 6.5epss 0.01

    The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able to write objects…

  • CVE-2026-48726MedJun 1, 2026
    risk 0.35cvss 6.5epss 0.01

    A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` did not actually reach the underlying `revoke_token()` call, so the JWT remained…

  • CVE-2026-42360MedJun 1, 2026
    risk 0.35cvss 6.5epss 0.01

    A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_key` keys inside a JSON template structure) to be bypassed when the rendered field exceeded `[core] max_templated_field_length`:…

  • CVE-2026-42358MedJun 1, 2026
    risk 0.35cvss 6.5epss 0.01

    A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `secret`, `api_key`) to be bypassed when the JSON value's nesting depth exceeded the shared secrets masker's recursion limit: the…

  • CVE-2026-40861MedJun 1, 2026
    risk 0.35cvss 6.5epss 0.01

    A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process (read-path attack — e.g. `/etc/passwd` or `airflow.cfg`) or (b) supply a `task_id` containing `..` sequences accepted by the Task…

  • CVE-2026-45192MedJun 1, 2026
    risk 0.35cvss 6.5epss 0.01

    A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission to retrieve secrets stored in a Connection's `extra` JSON blob under field names not present in the redaction allowlist…

Page 5 of 10