apache-airflow vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-57735Criticalapache-airflow: Apache Airflow: JWT token still valid after logoutCVE-2026-34538Mediumapache-airflow: Apache Airflow has an authorization bypass in DagRun wait endpointCVE-2026-32794Mediumapache-airflow: Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token ExchangeCVE-2026-30911Highapache-airflow: Apache Airflow: Execution API HITL Endpoints Missing Per-Task AuthorizationCVE-2026-28779Highapache-airflow: Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applicationsCVE-2026-28563Mediumapache-airflow: Apache Airflow: DAG authorization bypassCVE-2026-26929Highapache-airflow: Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks MetadataCVE-2025-27555Mediumapache-airflow: Apache Airflow exposes sensitive information in its log filesCVE-2024-56373Highapache-airflow: Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate tableCVE-2025-65995Mediumapache-airflow: Apache Airflow error reporting may expose full kwargsCVE-2026-22922Mediumapache-airflow: Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log AccessCVE-2026-24098Mediumapache-airflow: Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated UsersCVE-2025-68675Highapache-airflow: Apache Airflow proxy credentials for various providers might leak in task logsCVE-2025-68438Highapache-airflow: Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncatedCVE-2025-66388Mediumapache-airflow: Apache Airflow exposes secret values to authenticated UI users via rendered templatesCVE-2025-62503Mediumapache-airflow: Apache Airflow's create action can upsert existing Pools/Connections/VariablesCVE-2025-62402Mediumapache-airflow: Apache Airflow `/api/v2/dagReports` executes DAG Python in APICVE-2025-54941Mediumapache-airflow: Apache Airflow has a command injection vulnerability in "example_dag_decorator"CVE-2025-54831Mediumapache-airflow: Apache Airflow: Connection sensitive details exposed to users with READ permissionsCVE-2024-50378Lowapache-airflow: Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent DataCVE-2024-45034Highapache-airflow: Apache Airflow vulnerable to Execution with Unnecessary PrivilegesCVE-2024-45498Highapache-airflow: Apache Airflow vulnerable to Improper Encoding or Escaping of OutputCVE-2024-41937Mediumapache-airflow: Apache Airflow Cross-site Scripting VulnerabilityCVE-2024-39877Highapache-airflow: Apache Airflow has DAG Author Code Execution possibility in airflow-schedulerCVE-2024-39863Mediumapache-airflow: Apache Airflow Potential Cross-site Scripting Vulnerability

Stop the waste.
Protect your environment with Kodem.