product of apache

airflow

23 thingsrelated by NVD

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting…
CVE-2026-86473
Severity critical
When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the…
CVE-2026-82355
Severity medium
Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags…
CVE-2026-75158
Severity medium
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on…
CVE-2026-68971
Severity medium
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in…
CVE-2026-68970
Severity medium
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the…
CVE-2026-68969
Severity medium
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed…
CVE-2026-68968
Severity high
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard…
CVE-2026-68076
Severity medium
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by…
CVE-2026-67587
Severity high
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That…
CVE-2026-67260
Severity high
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has…
CVE-2026-65017
Severity medium
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value…
CVE-2026-59244
Severity medium
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through…
CVE-2026-59242
Severity medium
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized…
CVE-2026-58076
Severity high
Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's…
CVE-2026-54183
Severity medium
In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without…
CVE-2026-49487
Severity medium
Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file…
CVE-2026-49296
Severity medium
The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like…
CVE-2026-48892
Severity medium
A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized…
CVE-2026-48891
Severity medium
The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based…
CVE-2026-48828
Severity medium
Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay…
CVE-2025-66236
Severity high
When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case…
CVE-2025-57735
Severity critical
The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that…
CVE-2025-54550
Severity high