Apache
Apache Airflow: vulnerabilities and CVEs
Apache Airflow has 161 published vulnerabilities, 70 of them in the last 12 months. 15 are rated critical and 2 are listed by CISA as actively exploited.
CVEs161
Last 12 months70
Critical15
Actively exploited2
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11978 | High (8.8) | 99% | ⚠ Active exploitation | Jul 17, 2020 | An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to… |
| CVE-2020-13927 | Critical (9.8) | 100% | ⚠ Active exploitation | Nov 10, 2020 | The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86473 | Critical (9.1) | 0.75% | — | Sep 21, 2026 | Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns… |
| CVE-2026-82355 | Medium (4.2) | 0.73% | — | Sep 21, 2026 | When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended… |
| CVE-2026-75158 | Medium (4.3) | 0.64% | — | Sep 21, 2026 | Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access… |
| CVE-2026-75157 | High (7.5) | 0.44% | — | Sep 18, 2026 | Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset… |
| CVE-2026-68971 | Medium (6.5) | 0.59% | — | Aug 12, 2026 | Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other… |
| CVE-2026-68970 | Medium (6.5) | 0.39% | — | Aug 12, 2026 | Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only… |
| CVE-2026-68969 | Medium (6.5) | 0.64% | — | Aug 12, 2026 | Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The… |
| CVE-2026-68968 | High (7.5) | 0.75% | — | Aug 12, 2026 | Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route… |
| CVE-2026-68076 | Medium (5.4) | 0.62% | — | Aug 12, 2026 | Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern… |
| CVE-2026-67587 | High (8.8) | 1.2% | — | Aug 12, 2026 | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it… |
| CVE-2026-67260 | High (7.3) | 1.4% | — | Aug 12, 2026 | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a… |
| CVE-2026-65017 | Medium (6.5) | 0.70% | — | Aug 12, 2026 | Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer… |
| CVE-2026-59244 | Medium (6.5) | 0.39% | — | Aug 12, 2026 | Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and… |
| CVE-2026-59242 | Medium (5.4) | 0.80% | — | Aug 12, 2026 | Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an… |
| CVE-2026-58076 | High (8.8) | 0.92% | — | Aug 12, 2026 | Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction… |
| CVE-2026-54183 | Medium (4.3) | 0.64% | — | Aug 12, 2026 | Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond… |
| CVE-2026-68870 | Medium (5.3) | 0.36% | — | Aug 10, 2026 | The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment… |
| CVE-2026-49487 | Medium (6.5) | 0.66% | — | Jul 7, 2026 | In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key)… |
| CVE-2026-49296 | Medium (6.5) | 0.60% | — | Jul 7, 2026 | Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI… |
| CVE-2026-48892 | Medium (6.5) | 0.66% | — | Jul 7, 2026 | The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic… |
| CVE-2026-48891 | Medium (4.3) | 0.64% | — | Jul 7, 2026 | A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and… |
| CVE-2026-48828 | Medium (6.5) | 0.66% | — | Jul 7, 2026 | The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` /… |
| CVE-2026-33264 | Critical (9.8) | 1.6% | — | Jul 7, 2026 | A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger… |
| CVE-2026-49298 | High (8.8) | 0.81% | — | Jun 1, 2026 | A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An… |
| CVE-2026-49267 | Medium (5.9) | 0.27% | — | Jun 1, 2026 | Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote certificate when the deployment used `[email] smtp_starttls=True`… |
| CVE-2026-48726 | Medium (6.5) | 0.60% | — | Jun 1, 2026 | A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` did not actually… |
| CVE-2026-46764 | Medium (4.3) | 0.57% | — | Jun 1, 2026 | The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly by numeric ID after only the generic Audit Log permission check, while the collection endpoint `GET… |
| CVE-2026-45426 | Low (3.1) | 0.52% | — | Jun 1, 2026 | Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log server authorized JWT tokens against Dag IDs by applying… |
| CVE-2026-45360 | High (7.3) | 0.93% | — | Jun 1, 2026 | Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary class paths drawn from DAG-author-controlled serialized state without an… |
| CVE-2026-42360 | Medium (6.5) | 0.52% | — | Jun 1, 2026 | A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_key` keys inside a JSON template structure) to be bypassed when the… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.