cbcvebase.

Apache Software Foundation Apache Airflow vulnerabilities

124 known vulnerabilities affecting apache_software_foundation/apache_airflow.

Total CVEs
124
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
2
Severity breakdown
CRITICAL11HIGH38MEDIUM72LOW3

Vulnerabilities

Page 7 of 7
CVE-2023-45348P4MEDIUMCVSS 4.3≥ 2.4.0, < 2.7.02023-10-14
CVE-2023-45348 [MEDIUM] CWE-200 CVE-2023-45348: Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticate Apache Airflow, versions 2.7.0 and 2.7.1, is affected by a vulnerability that allows an authenticated user to retrieve sensitive configuration information when the "expose_config" option is set to "non-sensitive-only". The `expose_config` option is False by default. It is recommended to upgrade to a version that is not affected.
nvd
CVE-2026-32690P4LOWCVSS 3.7fixed in 3.2.22026-04-18
CVE-2026-32690 [LOW] CWE-668 CVE-2026-32690: Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented
nvd
CVE-2026-40963P4LOWCVSS 3.1≥ 3.0.0, < 3.2.22026-06-01
CVE-2026-40963 [LOW] CWE-285 CVE-2026-40963: The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Da The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags. An authenticated UI/API user authorized for one Dag could enumerate linked Dag IDs and dependency metadata for other Dags they were not authorized to read. Affects deploymen
nvd
CVE-2026-45426P4LOWCVSS 3.1≥ 3.0.0, < 3.2.22026-06-01
CVE-2026-45426 [LOW] CWE-863 CVE-2026-45426: Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log server authorized JWT tokens against Dag IDs by applying Python's `str.lstrip()` to the requested path segment when verifying the JWT's `sub` claim. `str.lstrip()` strips any of a *set* of cha
nvd
Apache Software Foundation Apache Airflow vulnerabilities | cvebase