apache-airflow vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-46764Mediumapache-airflow: Apache Airflow has an Authorization Bypass Through User-Controlled KeyCVE-2026-49267Mediumapache-airflow: Apache Airflow has no certificate validation on SMTP STARTTLS connectionsCVE-2026-48726Mediumapache-airflow: Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logoutCVE-2026-42360Mediumapache-airflow: Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized ActorCVE-2026-41084Highapache-airflow: Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled KeyCVE-2026-45426Lowapache-airflow: Apache Airflow has an Incorrect Authorization issueCVE-2026-42359Highapache-airflow: Apache Airflow has a Deserialization of Untrusted Data vulnerabilityCVE-2026-45360Highapache-airflow: Apache Airflow Vulnerable to Deserialization of Untrusted DataCVE-2026-42358Mediumapache-airflow: Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized ActorCVE-2026-42252Criticalapache-airflow: Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template EngineCVE-2026-41017Mediumapache-airflow: Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' AttributeCVE-2026-41014Mediumapache-airflow: Apache Airflow has a Missing Authorization issueCVE-2026-40961Highapache-airflow: Apache Airflow: Authenticated users can bypass the `is_safe_url` checkCVE-2026-40861Mediumapache-airflow: Apache Airflow has a Link Following issueCVE-2026-40963Lowapache-airflow: Apache Airflow has an Improper Authorization issueCVE-2026-45192Mediumapache-airflow: Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra`  to read-permitted usersCVE-2026-40690Mediumapache-airflow: Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissionsCVE-2026-38743Mediumapache-airflow: Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and…CVE-2026-32690Lowapache-airflow-core: Apache Airflow Exposes Secrets in Variables Saved as JSON DictionariesCVE-2026-31987Mediumapache-airflow: Apache Airflow: JWT token appearing in logsCVE-2025-54550Highapache-airflow: Apache Airflow: RCE by race condition in example_xcom dagCVE-2026-25219Mediumapache-airflow: Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view accessCVE-2026-33858Highapache-airflow: Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom APICVE-2025-66236Mediumapache-airflow: Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UICVE-2025-57735Criticalapache-airflow: Apache Airflow: JWT token still valid after logout

Stop the waste.
Protect your environment with Kodem.