Dependency scanning
Check whether apache-airflow is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-48828
Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API
CVE-2026-48828
Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API
CVE-2026-33264
CVE-2026-33264
CVE-2026-48891
CVE-2026-48891
CVE-2026-48892
CVE-2026-48892
CVE-2026-49487
CVE-2026-49487
CVE-2026-45360
Apache Airflow Vulnerable to Deserialization of Untrusted Data
CVE-2026-34538
Apache Airflow has an authorization bypass in DagRun wait endpoint
CVE-2025-66236
Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI
CVE-2025-68438
Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
CVE-2024-41937
Apache Airflow Cross-site Scripting Vulnerability
CVE-2025-57735
Apache Airflow: JWT token still valid after logout
CVE-2024-56373
Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
CVE-2026-22922
Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access
CVE-2025-65995
Apache Airflow error reporting may expose full kwargs
CVE-2025-27555
Apache Airflow exposes sensitive information in its log files
CVE-2026-24098
Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users
CVE-2025-68675
Apache Airflow proxy credentials for various providers might leak in task logs
CVE-2024-50378
Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
CVE-2024-45498
Apache Airflow vulnerable to Improper Encoding or Escaping of Output
CVE-2024-45034
Apache Airflow vulnerable to Execution with Unnecessary Privileges
CVE-2024-39877
Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
CVE-2024-39863
Apache Airflow Potential Cross-site Scripting Vulnerability
CVE-2024-25142
Apache Airflow does not return the "Cache-Control" header for dynamic content
CVE-2026-49487
Apache Airflow exposes deferred trigger kwargs in task-instance API responses
CVE-2026-48891
Apache Airflow exposes unreadable DAG identifiers in the scheduling dependencies graph
CVE-2026-48892
Apache Airflow exposes secrets backend credentials through the Config API
CVE-2026-33264
Apache Airflow allows code execution through unsafe serialized DAG deserialization
CVE-2026-54183
CVE-2026-54183
CVE-2026-67260
CVE-2026-67260
CVE-2026-68968
CVE-2026-68968
CVE-2026-68969
CVE-2026-68969
CVE-2026-67587
CVE-2026-67587
CVE-2026-59244
CVE-2026-59244
CVE-2026-68970
CVE-2026-68970
CVE-2026-68076
CVE-2026-68076
CVE-2026-49296
CVE-2026-49296
CVE-2026-49296
apache-airflow DAG source authorization bypass exposes co-located DAG source
CVE-2026-41017
CVE-2026-41017
CVE-2026-48726
CVE-2026-48726
CVE-2026-42360
CVE-2026-42360
CVE-2026-45360
CVE-2026-45360
CVE-2026-42359
CVE-2026-42359
CVE-2026-42252
CVE-2026-42252
CVE-2026-41084
CVE-2026-41084
CVE-2026-45192
CVE-2026-45192
CVE-2026-41014
CVE-2026-41014
CVE-2026-40861
CVE-2026-40861
CVE-2026-45426
CVE-2026-45426
CVE-2026-49267
Apache Airflow has no certificate validation on SMTP STARTTLS connections
CVE-2026-49267
Apache Airflow has no certificate validation on SMTP STARTTLS connections
CVE-2026-32690
CVE-2026-32690
CVE-2026-32690
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
CVE-2026-25917
CVE-2026-25917
CVE-2024-56373
Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
CVE-2025-65995
Apache Airflow error reporting may expose full kwargs
CVE-2025-54550
Apache Airflow: RCE by race condition in example_xcom dag
CVE-2025-54550
Apache Airflow: RCE by race condition in example_xcom dag
CVE-2023-46215
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
CVE-2023-46215
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
CVE-2026-25219
Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
CVE-2026-25219
Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
CVE-2023-51702
Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service
CVE-2023-51702
Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service
CVE-2026-32794
Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange
CVE-2023-39441
Apache Airflow missing Certificate Validation
CVE-2023-39441
Apache Airflow missing Certificate Validation
CVE-2026-40690
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
CVE-2026-40690
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
CVE-2026-46764
Apache Airflow has an Authorization Bypass Through User-Controlled Key
CVE-2026-46764
Apache Airflow has an Authorization Bypass Through User-Controlled Key
CVE-2025-27555
Apache Airflow exposes sensitive information in its log files
CVE-2026-31987
Apache Airflow: JWT token appearing in logs
CVE-2026-31987
Apache Airflow: JWT token appearing in logs
CVE-2026-40963
Apache Airflow has an Improper Authorization issue
CVE-2026-40963
Apache Airflow has an Improper Authorization issue
CVE-2026-38743
Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record
CVE-2026-38743
Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record
CVE-2026-42358
Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-42358
Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-40961
Apache Airflow: Authenticated users can bypass the `is_safe_url` check
CVE-2026-40961
Apache Airflow: Authenticated users can bypass the `is_safe_url` check
CVE-2026-30912
CVE-2026-30912
CVE-2026-32794
Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange
CVE-2026-45426
Apache Airflow has an Incorrect Authorization issue
CVE-2026-42359
Apache Airflow has a Deserialization of Untrusted Data vulnerability
CVE-2026-42360
Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-41084
Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key
CVE-2026-41014
Apache Airflow has a Missing Authorization issue
CVE-2026-41017
Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2026-40861
Apache Airflow has a Link Following issue
CVE-2026-42252
Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-48726
Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout
CVE-2026-45192
Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra` to read-permitted users
CVE-2023-28707
CVE-2023-28707
CVE-2025-62503
Apache Airflow's create action can upsert existing Pools/Connections/Variables
CVE-2025-62503
Apache Airflow's create action can upsert existing Pools/Connections/Variables
CVE-2024-42447
CVE-2024-42447
CVE-2024-29735
Apache Airflow Improper Preservation of Permissions vulnerability
CVE-2024-29735
Apache Airflow Improper Preservation of Permissions vulnerability
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes