CVE-2026-86473Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry Exploitation status Not known exploited Fix YesPublished 09/21/2026 Severity Critical CVE-2026-75158Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter Exploitation status Not known exploited Fix YesPublished 09/21/2026 Severity Medium CVE-2026-82355Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation Exploitation status Not known exploited Fix YesPublished 09/21/2026 Severity Medium CVE-2026-75157Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression) Exploitation status Not known exploited Fix YesPublished 09/18/2026 Severity High CVE-2026-59244Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI Exploitation status Not known exploited Fix YesPublished 08/12/2026 Severity Medium CVE-2026-58076Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server Exploitation status Not known exploited Fix YesPublished 08/12/2026 Severity High CVE-2026-59242Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint Exploitation status Not known exploited Fix YesPublished 08/12/2026 Severity Medium CVE-2026-54183Apache Airflow: Airflow Variables were not masked in the UI for authenticated users Exploitation status Not known exploited Fix YesPublished 08/12/2026 Severity Medium CVE-2026-67260Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization Exploitation status Not known exploited Fix YesPublished 08/12/2026 Severity High CVE-2026-67587Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget Exploitation status Not known exploited Fix YesPublished 08/12/2026 Severity High CVE-2026-65017Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass) Exploitation status Not known exploited Fix YesPublished 08/12/2026 Severity Medium CVE-2026-68968Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id Exploitation status Not known exploited Fix YesPublished 08/12/2026 Severity High CVE-2026-68969Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext Exploitation status Not known exploited Fix YesPublished 08/12/2026 Severity Medium CVE-2026-68970Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI Exploitation status Not known exploited Fix YesPublished 08/12/2026 Severity Medium CVE-2026-68971Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints Exploitation status Not known exploited Fix YesPublished 08/12/2026 Severity Medium CVE-2026-68076Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection Exploitation status Not known exploited Fix YesPublished 08/12/2026 Severity Medium CVE-2026-33264Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize() Exploitation status Not known exploited Fix YesPublished 07/07/2026 Severity Critical CVE-2026-49487Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs Exploitation status Not known exploited Fix YesPublished 07/07/2026 Severity Medium CVE-2026-48828Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key Exploitation status Not known exploited Fix YesPublished 07/07/2026 Severity Medium CVE-2026-49296Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id} Exploitation status Not known exploited Fix YesPublished 07/07/2026 Severity Medium CVE-2026-48891Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target Exploitation status Not known exploited Fix YesPublished 07/07/2026 Severity Medium CVE-2026-48892Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options Exploitation status Not known exploited Fix YesPublished 07/07/2026 Severity Medium CVE-2026-40861Apache Airflow: Arbitrary File Read via Log Symlink following in FileTaskHandler Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity Medium CVE-2026-40961Apache Airflow: Open Redirect Bypass Vulnerability Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity High CVE-2026-40963Apache Airflow: DAG authorization bypass on /ui/structure/structure_data Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity Low CVE-2026-41014Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity Medium CVE-2026-49267Apache Airflow: No certificate validation on SMTP STARTTLS connections Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity Medium CVE-2026-41017Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxy Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity Medium CVE-2026-41084Apache Airflow: API authorization bypass: bulk TaskInstances allows cross-DAG mutation Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity High CVE-2026-42252Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user pattern Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity Critical CVE-2026-42360Apache Airflow: Rendered template truncation bypasses nested sensitive-key masking Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity Medium CVE-2026-42358Apache Airflow: Variable masker depth-limit bypass returns cleartext nested secrets Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity Medium CVE-2026-42359Apache Airflow: Authenticated RCE via XCom PATCH endpoint — XComUpdateBody missing FORBIDDEN_XCOM_KEYS validator Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity High CVE-2026-45360Apache Airflow: Arbitrary import in custom deadline-reference deserialization Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity High CVE-2026-45426Apache Airflow: Log server JWT authorization bypass via Python lstrip() character stripping allows cross-Dag log access Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity Low CVE-2026-46764Apache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permission filter Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity Medium CVE-2026-48726Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity Medium CVE-2026-49298Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity High CVE-2026-45192Apache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API Response Exploitation status Not known exploited Fix YesPublished 06/01/2026 Severity Medium CVE-2026-38743Apache Airflow: Dags endpoint might provide access to otherwise inaccessible entities Exploitation status Not known exploited Fix YesPublished 04/24/2026 Severity Medium CVE-2026-40690Apache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users Exploitation status Not known exploited Fix YesPublished 04/24/2026 Severity Medium CVE-2026-40948Apache Airflow Providers Keycloak: OAuth Login CSRF — Missing State Parameter in Keycloak Auth Manager Exploitation status Not known exploited Fix YesPublished 04/18/2026 Severity Medium CVE-2026-32690Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1 Exploitation status Not known exploited Fix YesPublished 04/18/2026 Severity Low CVE-2026-30898Apache Airflow: Bad example of BashOperator shell injection via dag_run.conf Exploitation status Not known exploited Fix YesPublished 04/18/2026 Severity High CVE-2026-30912Apache Airflow: Exposing stack trace in case of constraint error Exploitation status Not known exploited Fix YesPublished 04/18/2026 Severity High CVE-2026-25917Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5) Exploitation status Not known exploited Fix YesPublished 04/18/2026 Severity High CVE-2026-32228Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to Exploitation status Not known exploited Fix YesPublished 04/18/2026 Severity High CVE-2026-31987Apache Airflow: JWT token appearing in logs Exploitation status Not known exploited Fix YesPublished 04/16/2026 Severity High CVE-2026-25219Apache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access Exploitation status Not known exploited Fix YesPublished 04/15/2026 Severity Medium CVE-2025-54550Apache Airflow: RCE by race condition in example_xcom dag Exploitation status Not known exploited Fix YesPublished 04/15/2026 Severity High CVE-2026-33858Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API Exploitation status Not known exploited Fix YesPublished 04/13/2026 Severity High CVE-2025-66236Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI Exploitation status Not known exploited Fix YesPublished 04/13/2026 Severity High CVE-2025-57735Apache Airflow: Airflow Logout Not Invalidating JWT Exploitation status Not known exploited Fix YesPublished 04/09/2026 Severity Critical CVE-2026-34538Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure) Exploitation status Not known exploited Fix YesPublished 04/09/2026 Severity Medium CVE-2026-28563Apache Airflow: DAG authorization bypass Exploitation status Not known exploited Fix YesPublished 03/17/2026 Severity Medium CVE-2026-26929Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata Exploitation status Not known exploited Fix YesPublished 03/17/2026 Severity Medium CVE-2026-30911Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization Exploitation status Not known exploited Fix YesPublished 03/17/2026 Severity High CVE-2026-28779Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications Exploitation status Not known exploited Fix YesPublished 03/17/2026 Severity High CVE-2025-27555Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli Exploitation status Not known exploited Fix YesPublished 02/24/2026 Severity Medium CVE-2024-56373Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information Exploitation status Not known exploited Fix YesPublished 02/24/2026 Severity High CVE-2025-65995Apache Airflow: Disclosure of secrets to UI via kwargs Exploitation status Not known exploited Fix YesPublished 02/21/2026 Severity Medium CVE-2026-22922Apache Airflow: Airflow externalLogUrl Permission Bypass Exploitation status Not known exploited Fix YesPublished 02/09/2026 Severity Medium CVE-2026-24098Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors Exploitation status Not known exploited Fix YesPublished 02/09/2026 Severity Medium CVE-2025-68675Apache Airflow: proxy credentials for various providers might leak in task logs Exploitation status Not known exploited Fix YesPublished 01/16/2026 Severity High CVE-2025-68438Apache Airflow: Secrets in rendered templates could contain parts of sensitive values when truncated Exploitation status Not known exploited Fix YesPublished 01/16/2026 Severity High CVE-2025-66388Apache Airflow: Secrets in rendered templates not redacted properly and exposed in the UI Exploitation status Not known exploited Fix YesPublished 12/15/2025 Severity Medium CVE-2025-54941Apache Airflow: Command injection in "example_dag_decorator" Exploitation status Not known exploited Fix YesPublished 10/30/2025 Severity Medium CVE-2025-62402Apache Airflow: Airflow 3 API: /api/v2/dagReports executes DAG Python in API Exploitation status Not known exploited Fix YesPublished 10/30/2025 Severity Medium CVE-2025-62503Apache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables) Exploitation status Not known exploited Fix YesPublished 10/30/2025 Severity Medium CVE-2025-54831Apache Airflow: Connection sensitive details exposed to users with READ permissions Exploitation status Not known exploited Fix Not confirmed Published 09/26/2025 Severity Medium CVE-2024-45784Apache Airflow: Sensitive configuration values are not masked in the logs by default Exploitation status Not known exploited Fix YesPublished 11/15/2024 Severity High CVE-2024-50378Apache Airflow: Secrets not masked in UI when sensitive variables are set via Airflow cli Exploitation status Not known exploited Fix YesPublished 11/08/2024 Severity Medium CVE-2024-45034Apache Airflow: Authenticated DAG authors could execute code on scheduler nodes Exploitation status Not known exploited Fix YesPublished 09/07/2024 Severity High CVE-2024-45498Apache Airflow: Command Injection in an example DAG Exploitation status Not known exploited Fix YesPublished 09/07/2024 Severity High CVE-2024-41937Apache Airflow: Stored XSS Vulnerability on provider link Exploitation status Not known exploited Fix YesPublished 08/21/2024 Severity Medium CVE-2024-39877Apache Airflow: DAG Author Code Execution possibility in airflow-scheduler Exploitation status Public exploit Fix YesPublished 07/17/2024 Severity High CVE-2024-39863Apache Airflow: Potential XSS Vulnerability Exploitation status Not known exploited Fix YesPublished 07/17/2024 Severity High CVE-2024-25142Apache Airflow: Cache Control - Storage of Sensitive Data in Browser Cache Exploitation status Not known exploited Fix YesPublished 06/14/2024 Severity Medium CVE-2024-32077Apache Airflow: XSS vulnerability in Task Instance Log/Log Details Exploitation status Not known exploited Fix YesPublished 05/14/2024 Severity Medium CVE-2024-31869Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used Exploitation status Not known exploited Fix YesPublished 04/18/2024 Severity Medium CVE-2024-29735Apache Airflow: Potentially harmful permission changing by log task handler Exploitation status Not known exploited Fix YesPublished 03/26/2024 Severity Medium CVE-2024-28746Apache Airflow: Ignored Airflow Permissions Exploitation status Not known exploited Fix YesPublished 03/14/2024 Severity High CVE-2024-26280Apache Airflow: Overly broad default permissions for Viewer/Ops (audit logs) Exploitation status Not known exploited Fix YesPublished 03/01/2024 Severity Medium CVE-2024-27906Apache Airflow: Dag Code and Import Error Permissions Ignored Exploitation status Not known exploited Fix YesPublished 02/29/2024 Severity Medium CVE-2023-50944Apache Airflow: Bypass permission verification to read code of other dags Exploitation status Not known exploited Fix YesPublished 01/24/2024 Severity Medium CVE-2023-50943Apache Airflow: Potential pickle deserialization vulnerability in XComs Exploitation status Not known exploited Fix YesPublished 01/24/2024 Severity High CVE-2023-51702Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service Exploitation status Not known exploited Fix YesPublished 01/24/2024 Severity Medium CVE-2023-48291Apache Airflow: Improper access control to DAG resources Exploitation status Not confirmed Fix YesPublished 12/21/2023 Severity Unknown CVE-2023-50783Apache Airflow: Improper access control vulnerability on the "varimport" endpoint Exploitation status Not confirmed Fix YesPublished 12/21/2023 Severity Unknown CVE-2023-47265Apache Airflow: DAG Params alllow to embed unchecked Javascript Exploitation status Not confirmed Fix YesPublished 12/21/2023 Severity Unknown CVE-2023-49920Apache Airflow: Missing CSRF protection on DAG/trigger Exploitation status Not confirmed Fix YesPublished 12/21/2023 Severity Unknown CVE-2023-42781Apache Airflow: Permission verification bypass allows viewing dagruns of other dags Exploitation status Not known exploited Fix YesPublished 11/12/2023 Severity Unknown CVE-2023-47037Apache Airflow missing fix for CVE-2023-40611 in 2.7.1 (DAG run broken access) Exploitation status Not known exploited Fix YesPublished 11/12/2023 Severity Unknown CVE-2023-46215Apache Airflow Celery provider, Apache Airflow: Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend Exploitation status Not known exploited Fix YesPublished 10/28/2023 Severity High CVE-2023-46288Apache Airflow: Sensitive parameters exposed in API when "non-sensitive-only" configuration is set Exploitation status Not known exploited Fix YesPublished 10/23/2023 Severity Unknown CVE-2023-42663Apache Airflow: Bypass permission verification to view task instances of other dags Exploitation status Not confirmed Fix YesPublished 10/14/2023 Severity Unknown CVE-2023-42792Apache Airflow: Improper access control to DAG resources Exploitation status Not known exploited Fix YesPublished 10/14/2023 Severity Unknown CVE-2023-45348Apache Airflow: Configuration information leakage vulnerability Exploitation status Not known exploited Fix YesPublished 10/14/2023 Severity Unknown CVE-2023-42780Apache Airflow: Improper access control vulnerability in the "List dag warnings" feature Exploitation status Not known exploited Fix YesPublished 10/14/2023 Severity Unknown CVE-2023-40712Apache Airflow: Secrets can be unmasked in the "Rendered Template" Exploitation status Not known exploited Fix YesPublished 09/12/2023 Severity Unknown