VendorsApacheairflowall versions
Vulnerabilities

Apache Airflow

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

156CVEs
CVE-2026-34538
Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)
Published 2026-04-09 · Analyzed
6.5EPSS 0.007
CVE-2026-49487
Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs
Published 2026-07-07 · Analyzed
6.5EPSS 0.007
CVE-2026-48892
Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options
Published 2026-07-07 · Analyzed
6.5EPSS 0.007
CVE-2026-48828
Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key
Published 2026-07-07 · Analyzed
6.5EPSS 0.007
CVE-2026-25219
Apache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
Published 2026-04-15 · Analyzed
6.5EPSS 0.006
CVE-2025-66388
Apache Airflow: Secrets in rendered templates not redacted properly and exposed in the UI
Published 2025-12-15 · Modified
6.5EPSS 0.005
CVE-2026-45192
Apache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API Response
Published 2026-06-01 · Analyzed
6.5EPSS 0.004
CVE-2026-26929
Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata
Published 2026-03-17 · Modified
6.5EPSS 0.004
CVE-2026-49296
Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id}
Published 2026-07-07 · Analyzed
6.5EPSS 0.004
CVE-2026-65017
Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)
Published 2026-08-12 · Analyzed
6.5EPSS 0.004
CVE-2026-22922
Apache Airflow: Airflow externalLogUrl Permission Bypass
Published 2026-02-09 · Analyzed
6.5EPSS 0.004
CVE-2023-51702
Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service
Published 2024-01-24 · Modified
6.5EPSS 0.004
CVE-2026-48726
Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path
Published 2026-06-01 · Analyzed
6.5EPSS 0.004
CVE-2025-27555
Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli
Published 2026-02-24 · Modified
6.5EPSS 0.004
CVE-2026-68969
Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext
Published 2026-08-12 · Analyzed
6.5EPSS 0.004
CVE-2026-42358
Apache Airflow: Variable masker depth-limit bypass returns cleartext nested secrets
Published 2026-06-01 · Modified
6.5EPSS 0.003
CVE-2026-42360
Apache Airflow: Rendered template truncation bypasses nested sensitive-key masking
Published 2026-06-01 · Analyzed
6.5EPSS 0.003
CVE-2026-68971
Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints
Published 2026-08-12 · Analyzed
6.5EPSS 0.003
CVE-2026-59244
Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI
Published 2026-08-12 · Modified
6.5EPSS 0.002
CVE-2026-68970
Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI
Published 2026-08-12 · Analyzed
6.5EPSS 0.002
CVE-2022-45402
Apache Airflow: Open redirect during login
Published 2022-11-15 · Modified
6.1EPSS 0.818
CVE-2020-13944
In Apache Airflow < 1.10.12, the "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit.
Published 2020-09-17 · Modified
6.1EPSS 0.251
CVE-2020-17515
The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects Apache Airflow versions prior to 1.10.13. This is same as CVE-2020-13944 but the implemented fix in Airflow 1.10.13 did not fix the issue completely.
Published 2020-12-11 · Modified
6.1EPSS 0.162
CVE-2021-28359
Apache Airflow Reflected XSS via Origin Query Argument in URL
Published 2021-05-02 · Modified
6.1EPSS 0.144
CVE-2020-9485
An issue was found in Apache Airflow versions 1.10.10 and below. A stored XSS vulnerability was discovered in the Chart pages of the the "classic" UI.
Published 2020-07-16 · Modified
6.1EPSS 0.028
CVE-2021-45229
Apache Airflow: Reflected XSS via Origin Query Argument in URL
Published 2022-02-25 · Modified
6.1EPSS 0.026
CVE-2017-12614
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above.
Published 2018-08-06 · Modified
6.1EPSS 0.020
CVE-2022-40754
Open Redirect
Published 2022-09-21 · Modified
6.1EPSS 0.017
CVE-2024-41937
Apache Airflow: Stored XSS Vulnerability on provider link
Published 2024-08-21 · Modified
6.1EPSS 0.017
CVE-2022-43985
Apache Airflow prior to 2.4.2 has an open redirect
Published 2022-11-02 · Modified
6.1EPSS 0.016
CVE-2022-43982
Apache Airflow prior to 2.4.2 allows reflected XSS via Origin Query Argument in URL
Published 2022-11-02 · Modified
6.1EPSS 0.015
CVE-2023-39441
Apache Airflow SMTP Provider, Apache Airflow IMAP Provider, Apache Airflow: SMTP/IMAP client components allowed MITM due to missing Certificate Validation
Published 2023-08-23 · Modified
5.9EPSS 0.008
CVE-2026-41017
Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxy
Published 2026-06-01 · Modified
5.9EPSS 0.004
CVE-2024-27906
Apache Airflow: Dag Code and Import Error Permissions Ignored
Published 2024-02-29 · Modified
5.9EPSS 0.003
CVE-2026-41016
Apache Airflow Providers SMTP: No certificate validation on SMTP STARTTLS connections in SMTP provider
Published 2026-04-30 · Analyzed
5.9EPSS 0.003
CVE-2026-49267
Apache Airflow: No certificate validation on SMTP STARTTLS connections
Published 2026-06-01 · Analyzed
5.9EPSS 0.002
CVE-2018-20244
In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
Published 2019-02-27 · Modified
5.5EPSS 0.020
CVE-2022-40954
Apache Airflow Spark Provider RCE that bypass restrictions to read arbitrary files
Published 2022-11-22 · Modified
5.5EPSS 0.014
CVE-2024-25142
Apache Airflow: Cache Control - Storage of Sensitive Data in Browser Cache
Published 2024-06-14 · Modified
5.5EPSS 0.003
CVE-2023-29247
Stored XSS on Apache Airflow
Published 2023-05-08 · Modified
5.4EPSS 0.020
← Prev3 / 4Next →