Launch Week Day 1: Announcing Security Design Review
pypi

apache-airflow

View on pypi registry
100 Total advisories
100 Vulnerabilities
0 Malware

Vulnerabilities

UNKNOWN
PyPI

CVE-2024-28746

CVE-2024-28746

UNKNOWN
PyPI

CVE-2024-26280

CVE-2024-26280

HIGH 7.5
PyPI

CVE-2025-68675

CVE-2025-68675

HIGH 8.8
PyPI

CVE-2024-45498

CVE-2024-45498

UNKNOWN
PyPI

CVE-2023-50944

CVE-2023-50944

UNKNOWN
PyPI

CVE-2023-50943

CVE-2023-50943

MEDIUM 6.5
PyPI

CVE-2026-22922

CVE-2026-22922

MEDIUM 5.4
PyPI

CVE-2024-32077

CVE-2024-32077

UNKNOWN
PyPI

CVE-2023-35005

CVE-2023-35005

UNKNOWN
PyPI

CVE-2023-29247

CVE-2023-29247

UNKNOWN
PyPI

CVE-2023-25754

CVE-2023-25754

MEDIUM 6.5
PyPI

CVE-2026-34538

CVE-2026-34538

HIGH 7.5
PyPI

CVE-2025-66236

CVE-2025-66236

HIGH 7.5
PyPI

CVE-2025-68438

CVE-2025-68438

LOW 3.7
PyPI

CVE-2026-32690

CVE-2026-32690

HIGH 8.1
PyPI

CVE-2026-30911

CVE-2026-30911

HIGH 8.8
PyPI

CVE-2026-33858

CVE-2026-33858

HIGH 7.5
PyPI

CVE-2026-28779

CVE-2026-28779

MEDIUM 4.3
PyPI

CVE-2026-28563

CVE-2026-28563

MEDIUM 6.5
PyPI

CVE-2026-24098

CVE-2026-24098

MEDIUM 6.5
PyPI

CVE-2025-54831

CVE-2025-54831

MEDIUM 6.5
PyPI

CVE-2025-66388

CVE-2025-66388

MEDIUM 6.5
PyPI

CVE-2026-26929

CVE-2026-26929

UNKNOWN
PyPI

CVE-2024-27906

CVE-2024-27906

UNKNOWN
PyPI

CVE-2024-45034

CVE-2024-45034

MEDIUM 5.5
PyPI

CVE-2024-25142

CVE-2024-25142

HIGH 8.8
PyPI

CVE-2024-39877

CVE-2024-39877

MEDIUM 6.1
PyPI

CVE-2024-41937

CVE-2024-41937

MEDIUM 5.4
PyPI

CVE-2024-39863

CVE-2024-39863

MEDIUM 6.5
PyPI

CVE-2023-50783

CVE-2023-50783

MEDIUM 6.5
PyPI

CVE-2023-42792

CVE-2023-42792

MEDIUM 6.5
PyPI

CVE-2023-49920

CVE-2023-49920

MEDIUM 4.3
PyPI

CVE-2023-45348

CVE-2023-45348

MEDIUM 6.5
PyPI

CVE-2023-42780

CVE-2023-42780

UNKNOWN
PyPI

CVE-2023-25695

CVE-2023-25695

UNKNOWN
PyPI

CVE-2023-42663

CVE-2023-42663

UNKNOWN
PyPI

CVE-2023-47037

CVE-2023-47037

MEDIUM 4.3
PyPI

CVE-2023-48291

CVE-2023-48291

MEDIUM 5.4
PyPI

CVE-2023-47265

CVE-2023-47265

UNKNOWN
PyPI

CVE-2023-40712

CVE-2023-40712

UNKNOWN
PyPI

CVE-2023-42781

CVE-2023-42781

MEDIUM 4.3
PyPI

CVE-2023-46288

CVE-2023-46288

UNKNOWN
PyPI

CVE-2023-40611

CVE-2023-40611

HIGH 8.1
PyPI

CVE-2023-37379

CVE-2023-37379

UNKNOWN
PyPI

CVE-2023-39508

CVE-2023-39508

UNKNOWN
PyPI

CVE-2023-35908

CVE-2023-35908

UNKNOWN
PyPI

CVE-2023-36543

CVE-2023-36543

HIGH 8.0
PyPI

CVE-2023-40273

CVE-2023-40273

UNKNOWN
PyPI

CVE-2022-40754

CVE-2022-40754

UNKNOWN
PyPI

CVE-2022-27949

CVE-2022-27949

UNKNOWN
PyPI

CVE-2022-43985

CVE-2022-43985

UNKNOWN
PyPI

CVE-2023-22887

CVE-2023-22887

UNKNOWN
PyPI

CVE-2022-41672

CVE-2022-41672

UNKNOWN
PyPI

CVE-2022-45402

CVE-2022-45402

UNKNOWN
PyPI

CVE-2022-46651

CVE-2022-46651

UNKNOWN
PyPI

CVE-2022-40127

CVE-2022-40127

UNKNOWN
PyPI

CVE-2022-43982

CVE-2022-43982

UNKNOWN
PyPI

CVE-2023-22888

CVE-2023-22888

UNKNOWN
PyPI

CVE-2022-40604

CVE-2022-40604

UNKNOWN
PyPI

CVE-2017-12614

CVE-2017-12614

UNKNOWN
PyPI

CVE-2025-66236

Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI

LOW 3.7
PyPI

CVE-2026-32690

Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries

HIGH 8.8
PyPI

CVE-2026-33858

Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API

UNKNOWN
PyPI

CVE-2025-54831

Apache Airflow: Connection sensitive details exposed to users with READ permissions

HIGH 8.8
PyPI

CVE-2024-45498

Apache Airflow vulnerable to Improper Encoding or Escaping of Output

MEDIUM 6.5
PyPI

CVE-2026-34538

Apache Airflow has an authorization bypass in DagRun wait endpoint

MEDIUM 5.4
PyPI

CVE-2024-32077

Apache Airflow: XSS vulnerability in Task Instance Log/Log Details

MEDIUM 4.3
PyPI

CVE-2026-28563

Apache Airflow: DAG authorization bypass

HIGH 7.5
PyPI

CVE-2025-68675

Apache Airflow proxy credentials for various providers might leak in task logs

HIGH 8.1
PyPI

CVE-2026-30911

Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization

MEDIUM 6.5
PyPI

CVE-2025-66388

Apache Airflow exposes secret values to authenticated UI users via rendered templates

HIGH 7.5
PyPI

CVE-2025-68438

Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated

HIGH 7.5
PyPI

CVE-2026-26929

Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata

HIGH 7.5
PyPI

CVE-2026-28779

Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications

MEDIUM 6.5
PyPI

CVE-2026-22922

Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access

HIGH 7.5
PyPI

CVE-2026-41084

CVE-2026-41084

MEDIUM 4.3
PyPI

CVE-2026-41014

CVE-2026-41014

HIGH 7.3
PyPI

CVE-2026-45360

CVE-2026-45360

LOW 3.1
PyPI

CVE-2026-45426

CVE-2026-45426

HIGH 8.8
PyPI

CVE-2026-42359

CVE-2026-42359

MEDIUM 6.5
PyPI

CVE-2026-45192

CVE-2026-45192

MEDIUM 6.5
PyPI

CVE-2026-48726

CVE-2026-48726

MEDIUM 5.9
PyPI

CVE-2026-41017

CVE-2026-41017

MEDIUM 6.5
PyPI

CVE-2026-40861

CVE-2026-40861

CRITICAL 9.1
PyPI

CVE-2026-42252

CVE-2026-42252

MEDIUM 6.5
PyPI

CVE-2026-42360

CVE-2026-42360

CRITICAL 9.8
PyPI

CVE-2024-42447

CVE-2024-42447

HIGH 7.5
PyPI

CVE-2026-30912

CVE-2026-30912

HIGH 7.2
PyPI

CVE-2026-25917

CVE-2026-25917

CRITICAL 9.8
PyPI

CVE-2025-67895

CVE-2025-67895

CRITICAL 9.8
PyPI

CVE-2023-25693

CVE-2023-25693

MEDIUM 6.5
PyPI

CVE-2026-24098

Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users

MEDIUM 4.3
PyPI

CVE-2026-40690

Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions

MEDIUM 4.3
PyPI

CVE-2026-38743

Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record

HIGH 7.5
PyPI

CVE-2026-31987

Apache Airflow: JWT token appearing in logs

HIGH 8.1
PyPI

CVE-2025-54550

Apache Airflow: RCE by race condition in example_xcom dag

MEDIUM 6.5
PyPI

CVE-2026-25219

Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

CRITICAL 9.1
PyPI

CVE-2025-57735

Apache Airflow: JWT token still valid after logout

MEDIUM 4.8
PyPI

CVE-2026-32794

Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange

MEDIUM 6.5
PyPI

CVE-2025-27555

Apache Airflow exposes sensitive information in its log files

Ready to move

Start Securing

Free, no credit card | First findings in minutes