cbcvebase.

Apache Apache-Airflow-Providers-Cncf-Kubernetes vulnerabilities

3 known vulnerabilities affecting apache/apache-airflow-providers-cncf-kubernetes.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-27173P3HIGHCVSS 8.7fixed in 10.17.02026-05-19
CVE-2026-27173 [HIGH] CWE-538 CVE-2026-27173: JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks.
nvd
CVE-2023-33234P3HIGHCVSS 7.2≥ 5.0.0, < 7.0.02023-05-30
CVE-2023-33234 [HIGH] CWE-74 CVE-2023-33234: Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to cha Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. Operators should upgrade to provider version 7.0
nvd
CVE-2023-51702P3MEDIUMCVSS 6.5≥ 5.2.0, < 7.0.02024-01-24
CVE-2023-51702 [MEDIUM] CWE-312 CVE-2023-51702: Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. Additionally, if used with an Airflow version between 2.3.0 and 2.6.0, the configura
nvd