VendorsApacheairflowany version
Vulnerabilities

Apache Airflow any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

150CVEs
CVE-2026-68076
Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection
Published 2026-08-12 · Modified
5.4EPSS 0.006
CVE-2025-62402
Apache Airflow: Airflow 3 API: /api/v2/dagReports executes DAG Python in API
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2021-35936
No Authentication on Logging Server
Published 2021-08-16 · Modified
5.3EPSS 0.055
CVE-2020-17513
In Apache Airflow versions prior to 1.10.13, the Charts and Query View of the old (Flask-admin based) UI were vulnerable for SSRF attack.
Published 2020-12-14 · Modified
5.3EPSS 0.044
CVE-2024-29735
Apache Airflow: Potentially harmful permission changing by log task handler
Published 2024-03-26 · Analyzed
5.3EPSS 0.015
CVE-2023-25695
Information disclosure in Apache Airflow
Published 2023-03-15 · Modified
5.3EPSS 0.014
CVE-2024-31869
Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
Published 2024-04-18 · Modified
5.3EPSS 0.011
CVE-2024-50378
Apache Airflow: Secrets not masked in UI when sensitive variables are set via Airflow cli
Published 2024-11-08 · Analyzed
4.9EPSS 0.012
CVE-2019-12398
In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. The new "RBAC" UI is unaffected.
Published 2020-01-14 · Modified
4.8EPSS 0.028
CVE-2019-0216
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
Published 2019-04-10 · Modified
4.8EPSS 0.027
CVE-2019-12417
A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.
Published 2019-10-30 · Modified
4.8EPSS 0.013
CVE-2024-26280
Apache Airflow: Overly broad default permissions for Viewer/Ops (audit logs)
Published 2024-03-01 · Analyzed
4.7EPSS 0.019
CVE-2022-38170
Overly permissive umask for daemons
Published 2022-09-02 · Modified
4.7EPSS 0.006
CVE-2025-54941
Apache Airflow: Command injection in "example_dag_decorator"
Published 2025-10-30 · Modified
4.6EPSS 0.005
CVE-2025-62503
Apache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables)
Published 2025-10-30 · Analyzed
4.6EPSS 0.004
CVE-2023-48291
Apache Airflow: Improper access control to DAG resources
Published 2023-12-21 · Modified
4.3EPSS 0.018
CVE-2023-40611
Apache Airflow Dag Runs Broken Access Control Vulnerability
Published 2023-09-12 · Modified
4.3EPSS 0.017
CVE-2023-47037
Apache Airflow missing fix for CVE-2023-40611 in 2.7.1 (DAG run broken access)
Published 2023-11-12 · Modified
4.3EPSS 0.015
CVE-2023-46288
Apache Airflow: Sensitive parameters exposed in API when "non-sensitive-only" configuration is set
Published 2023-10-23 · Modified
4.3EPSS 0.014
CVE-2023-45348
Apache Airflow: Configuration information leakage vulnerability
Published 2023-10-14 · Modified
4.3EPSS 0.012
CVE-2026-28563
Apache Airflow: DAG authorization bypass
Published 2026-03-17 · Analyzed
4.3EPSS 0.007
CVE-2026-54183
Apache Airflow: Airflow Variables were not masked in the UI for authenticated users
Published 2026-08-12 · Analyzed
4.3EPSS 0.006
CVE-2026-48891
Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target
Published 2026-07-07 · Analyzed
4.3EPSS 0.006
CVE-2026-46764
Apache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permission filter
Published 2026-06-01 · Modified
4.3EPSS 0.006
CVE-2026-38743
Apache Airflow: Dags endpoint might provide access to otherwise inaccessible entities
Published 2026-04-24 · Analyzed
4.3EPSS 0.006
CVE-2026-41014
Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints
Published 2026-06-01 · Analyzed
4.3EPSS 0.006
CVE-2026-40690
Apache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users
Published 2026-04-24 · Analyzed
4.3EPSS 0.006
CVE-2026-32690
Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
Published 2026-04-18 · Analyzed
3.7EPSS 0.007
CVE-2026-45426
Apache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access
Published 2026-06-01 · Analyzed
3.1EPSS 0.005
CVE-2026-40963
Apache Airflow: DAG authorization bypass on /ui/structure/structure_data
Published 2026-06-01 · Analyzed
3.1EPSS 0.005
← Prev4 / 4