Airflow
This hub aggregates every CVE we track for Airflow, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
155
CVEs tracked
13
Critical
44
High
2
In CISA KEV
Severity distribution
MEDIUM95HIGH44CRITICAL13LOW3
Monthly trend
2
0
2
0
0
0
0
0
0
0
0
0
1
3
0
1
2
5
4
15
0
17
6
12
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Airflow.
- CVE-2026-59244Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI6.5
- CVE-2026-58076Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server8.8
- CVE-2026-59242Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint5.4
- CVE-2026-54183Apache Airflow: Airflow Variables were not masked in the UI for authenticated users4.3
- CVE-2026-67260Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization7.3
- CVE-2026-67587Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget8.8
- CVE-2026-65017Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)6.5
- CVE-2026-68968Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id7.5
- CVE-2026-68969Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext6.5
- CVE-2026-68970Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI6.5
- CVE-2026-68971Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints6.5
- CVE-2026-68076Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection5.4
- CVE-2026-33264Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize()9.8
- CVE-2026-49487Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs6.5
- CVE-2026-48828Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key6.5
Product normalization is registry-driven with AI assist and human review. How it works