Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
226 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.39% | — | Apache Airflow Teradata ProviderAI | 29/9/2026 | 29/9/2026 | The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the… | |
| Pendiente de análisis | Media (6.3) | 0.22% | — | Apache Airflow Providers SnowflakeAI | 29/9/2026 | 29/9/2026 | Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to… | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Apache Airflow Providers GoogleAI | 29/9/2026 | 29/9/2026 | Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the… | |
| Pendiente de análisis | Media (6.5) | 0.28% | — | Apache Airflow Providers TeradataAI | 29/9/2026 | 29/9/2026 | Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into the `CREATE MULTISET TABLE ... LOCATION` statement whenever the bucket is private… | |
| Pendiente de análisis | Media (6.5) | 0.37% | — | Apache Airflow Hashicorp ProviderAI | 24/9/2026 | 25/9/2026 | Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a secret belonging to a different… | |
| Analizada | Crítica (9.1) | 0.75% | — | Apache Airflow | 21/9/2026 | 25/9/2026 | Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An… | |
| Analizada | Media (4.2) | 0.73% | — | Apache Airflow | 21/9/2026 | 25/9/2026 | When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over cookie. The request then executes -- and is recorded in the audit log -- as the… | |
| Analizada | Media (4.3) | 0.64% | — | Apache Airflow | 21/9/2026 | 25/9/2026 | Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore enumerate asset events — including the source Dag ID, task ID, run ID and event… | |
| Pendiente de análisis | Alta (7.5) | 0.44% | — | Apache AirflowAI | 18/9/2026 | 22/9/2026 | Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently suppressing asset-triggered scheduling for it — a state-changing action gated on a… | |
| Modificada | Media (6.5) | 0.81% | — | Apache-airflow-providers-akeyless | 16/9/2026 | 17/9/2026 | Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a secret belonging to a different team,… | |
| Analizada | Alta (8.8) | 1.2% | — | Apache-airflow-providers-apache-kafka | 16/9/2026 | 18/9/2026 | Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka client which invokes them. Deployments that have enabled the Kafka event producer… | |
| Analizada | Alta (8.1) | 0.37% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different client application can present it to Airflow and be authenticated as the… | |
| Analizada | Alta (7.2) | 1.0% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to accept an existing, unexpired token naming it, and lets that token mint a replacement — so the account… | |
| Analizada | Crítica (9.8) | 0.98% | — | Apache-airflow-providers-keycloak | 16/9/2026 | 18/9/2026 | Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow. No allowlist restricts which client ids may authenticate, so the credentials of an unrelated application that… | |
| Analizada | Crítica (9.1) | 0.81% | — | Apache-airflow-providers-keycloak | 16/9/2026 | 18/9/2026 | Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated cookies, and never checks that the two describe the same… | |
| Analizada | Crítica (9.1) | 0.83% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full access as that user after the password change, so the password reset does… | |
| Analizada | Crítica (9.8) | 0.98% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the session against the user's integer database identifier, so the comparison never matches… | |
| Analizada | Crítica (9.1) | 0.38% | — | Apache-airflow-providers-fab | 8/9/2026 | 18/9/2026 | Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft's **multi-tenant**… | |
| Analizada | Media (6.5) | 0.59% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manager distinguishes a team-scoped Dag from a global one by… | |
| Analizada | Media (6.5) | 0.39% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was… | |
| Analizada | Media (6.5) | 0.64% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and a bulk request nests its entities two… | |
| Analizada | Alta (7.5) | 0.75% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts values `int()` rejects (`1.0` coerces… | |
| Modificada | Media (5.4) | 0.62% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which team names are allowed to contain. When… | |
| Analizada | Alta (8.8) | 1.2% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not… | |
| Analizada | Alta (7.3) | 1.4% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module… |