pypi

apache-airflow

View on pypi registry
100 Total advisories
100 Vulnerabilities
0 Malware

Dependency scanning

Check whether apache-airflow is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.5
PyPI

CVE-2026-48828

Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API

MEDIUM 6.5
PyPI

CVE-2026-48828

Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API

CRITICAL 9.8
PyPI

CVE-2026-33264

CVE-2026-33264

MEDIUM 4.3
PyPI

CVE-2026-48891

CVE-2026-48891

MEDIUM 6.5
PyPI

CVE-2026-48892

CVE-2026-48892

MEDIUM 6.5
PyPI

CVE-2026-49487

CVE-2026-49487

HIGH 7.3
PyPI

CVE-2026-45360

Apache Airflow Vulnerable to Deserialization of Untrusted Data

MEDIUM 6.5
PyPI

CVE-2026-34538

Apache Airflow has an authorization bypass in DagRun wait endpoint

UNKNOWN
PyPI

CVE-2025-66236

Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI

HIGH 7.5
PyPI

CVE-2025-68438

Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated

MEDIUM 6.1
PyPI

CVE-2024-41937

Apache Airflow Cross-site Scripting Vulnerability

CRITICAL 9.1
PyPI

CVE-2025-57735

Apache Airflow: JWT token still valid after logout

HIGH 8.4
PyPI

CVE-2024-56373

Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table

MEDIUM 6.5
PyPI

CVE-2026-22922

Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access

MEDIUM 6.5
PyPI

CVE-2025-65995

Apache Airflow error reporting may expose full kwargs

MEDIUM 6.5
PyPI

CVE-2025-27555

Apache Airflow exposes sensitive information in its log files

MEDIUM 6.5
PyPI

CVE-2026-24098

Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users

HIGH 7.5
PyPI

CVE-2025-68675

Apache Airflow proxy credentials for various providers might leak in task logs

MEDIUM 6.5
PyPI

CVE-2024-50378

Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data

HIGH 8.8
PyPI

CVE-2024-45498

Apache Airflow vulnerable to Improper Encoding or Escaping of Output

HIGH 8.8
PyPI

CVE-2024-45034

Apache Airflow vulnerable to Execution with Unnecessary Privileges

HIGH 8.8
PyPI

CVE-2024-39877

Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler

MEDIUM 5.4
PyPI

CVE-2024-39863

Apache Airflow Potential Cross-site Scripting Vulnerability

UNKNOWN
PyPI

CVE-2024-25142

Apache Airflow does not return the "Cache-Control" header for dynamic content

MEDIUM 6.5
PyPI

CVE-2026-49487

Apache Airflow exposes deferred trigger kwargs in task-instance API responses

MEDIUM 4.3
PyPI

CVE-2026-48891

Apache Airflow exposes unreadable DAG identifiers in the scheduling dependencies graph

MEDIUM 6.5
PyPI

CVE-2026-48892

Apache Airflow exposes secrets backend credentials through the Config API

CRITICAL 9.8
PyPI

CVE-2026-33264

Apache Airflow allows code execution through unsafe serialized DAG deserialization

MEDIUM 4.3
PyPI

CVE-2026-54183

CVE-2026-54183

HIGH 7.3
PyPI

CVE-2026-67260

CVE-2026-67260

HIGH 7.5
PyPI

CVE-2026-68968

CVE-2026-68968

MEDIUM 6.5
PyPI

CVE-2026-68969

CVE-2026-68969

HIGH 8.8
PyPI

CVE-2026-67587

CVE-2026-67587

MEDIUM 6.5
PyPI

CVE-2026-59244

CVE-2026-59244

MEDIUM 6.5
PyPI

CVE-2026-68970

CVE-2026-68970

MEDIUM 5.4
PyPI

CVE-2026-68076

CVE-2026-68076

MEDIUM 6.5
PyPI

CVE-2026-49296

CVE-2026-49296

MEDIUM 6.5
PyPI

CVE-2026-49296

apache-airflow DAG source authorization bypass exposes co-located DAG source

MEDIUM 5.9
PyPI

CVE-2026-41017

CVE-2026-41017

MEDIUM 6.5
PyPI

CVE-2026-48726

CVE-2026-48726

MEDIUM 6.5
PyPI

CVE-2026-42360

CVE-2026-42360

HIGH 7.3
PyPI

CVE-2026-45360

CVE-2026-45360

HIGH 8.8
PyPI

CVE-2026-42359

CVE-2026-42359

CRITICAL 9.1
PyPI

CVE-2026-42252

CVE-2026-42252

HIGH 7.5
PyPI

CVE-2026-41084

CVE-2026-41084

MEDIUM 6.5
PyPI

CVE-2026-45192

CVE-2026-45192

MEDIUM 4.3
PyPI

CVE-2026-41014

CVE-2026-41014

MEDIUM 6.5
PyPI

CVE-2026-40861

CVE-2026-40861

LOW 3.1
PyPI

CVE-2026-45426

CVE-2026-45426

MEDIUM 5.9
PyPI

CVE-2026-49267

Apache Airflow has no certificate validation on SMTP STARTTLS connections

MEDIUM 5.9
PyPI

CVE-2026-49267

Apache Airflow has no certificate validation on SMTP STARTTLS connections

LOW 3.7
PyPI

CVE-2026-32690

CVE-2026-32690

LOW 3.7
PyPI

CVE-2026-32690

Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries

HIGH 7.2
PyPI

CVE-2026-25917

CVE-2026-25917

HIGH 8.4
PyPI

CVE-2024-56373

Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table

MEDIUM 6.5
PyPI

CVE-2025-65995

Apache Airflow error reporting may expose full kwargs

HIGH 8.1
PyPI

CVE-2025-54550

Apache Airflow: RCE by race condition in example_xcom dag

HIGH 8.1
PyPI

CVE-2025-54550

Apache Airflow: RCE by race condition in example_xcom dag

HIGH 7.5
PyPI

CVE-2023-46215

Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability

HIGH 7.5
PyPI

CVE-2023-46215

Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability

MEDIUM 6.5
PyPI

CVE-2026-25219

Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

MEDIUM 6.5
PyPI

CVE-2026-25219

Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

MEDIUM 6.5
PyPI

CVE-2023-51702

Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service

MEDIUM 6.5
PyPI

CVE-2023-51702

Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service

MEDIUM 4.8
PyPI

CVE-2026-32794

Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange

MEDIUM 5.9
PyPI

CVE-2023-39441

Apache Airflow missing Certificate Validation

MEDIUM 5.9
PyPI

CVE-2023-39441

Apache Airflow missing Certificate Validation

MEDIUM 4.3
PyPI

CVE-2026-40690

Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions

MEDIUM 4.3
PyPI

CVE-2026-40690

Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions

MEDIUM 4.3
PyPI

CVE-2026-46764

Apache Airflow has an Authorization Bypass Through User-Controlled Key

MEDIUM 4.3
PyPI

CVE-2026-46764

Apache Airflow has an Authorization Bypass Through User-Controlled Key

MEDIUM 6.5
PyPI

CVE-2025-27555

Apache Airflow exposes sensitive information in its log files

HIGH 7.5
PyPI

CVE-2026-31987

Apache Airflow: JWT token appearing in logs

HIGH 7.5
PyPI

CVE-2026-31987

Apache Airflow: JWT token appearing in logs

LOW 3.1
PyPI

CVE-2026-40963

Apache Airflow has an Improper Authorization issue

LOW 3.1
PyPI

CVE-2026-40963

Apache Airflow has an Improper Authorization issue

MEDIUM 4.3
PyPI

CVE-2026-38743

Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record

MEDIUM 4.3
PyPI

CVE-2026-38743

Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record

MEDIUM 6.5
PyPI

CVE-2026-42358

Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

MEDIUM 6.5
PyPI

CVE-2026-42358

Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

HIGH 7.2
PyPI

CVE-2026-40961

Apache Airflow: Authenticated users can bypass the `is_safe_url` check

HIGH 7.2
PyPI

CVE-2026-40961

Apache Airflow: Authenticated users can bypass the `is_safe_url` check

HIGH 7.5
PyPI

CVE-2026-30912

CVE-2026-30912

MEDIUM 4.8
PyPI

CVE-2026-32794

Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange

LOW 3.1
PyPI

CVE-2026-45426

Apache Airflow has an Incorrect Authorization issue

HIGH 8.8
PyPI

CVE-2026-42359

Apache Airflow has a Deserialization of Untrusted Data vulnerability

MEDIUM 6.5
PyPI

CVE-2026-42360

Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

HIGH 7.5
PyPI

CVE-2026-41084

Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key

MEDIUM 4.3
PyPI

CVE-2026-41014

Apache Airflow has a Missing Authorization issue

MEDIUM 5.9
PyPI

CVE-2026-41017

Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

MEDIUM 6.5
PyPI

CVE-2026-40861

Apache Airflow has a Link Following issue

CRITICAL 9.1
PyPI

CVE-2026-42252

Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine

MEDIUM 6.5
PyPI

CVE-2026-48726

Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout

MEDIUM 6.5
PyPI

CVE-2026-45192

Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra`  to read-permitted users

UNKNOWN
PyPI

CVE-2023-28707

CVE-2023-28707

MEDIUM 4.6
PyPI

CVE-2025-62503

Apache Airflow's create action can upsert existing Pools/Connections/Variables

MEDIUM 4.6
PyPI

CVE-2025-62503

Apache Airflow's create action can upsert existing Pools/Connections/Variables

CRITICAL 9.8
PyPI

CVE-2024-42447

CVE-2024-42447

MEDIUM 5.3
PyPI

CVE-2024-29735

Apache Airflow Improper Preservation of Permissions vulnerability

MEDIUM 5.3
PyPI

CVE-2024-29735

Apache Airflow Improper Preservation of Permissions vulnerability

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes