Apache Airflow Vulnerabilities

3 advisories affecting Apache Airflow

3

Total CVEs

0

Critical

3

High

CVE-2026-33858

Apr 13, 2026

High (8.8)

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly tru...

Read Advisory

CVE-2026-28779

Mar 17, 2026

High (7.5)

Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. This allows any application co-hoste...

Read Advisory

CVE-2026-30911

Mar 17, 2026

High (8.1)

Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, ...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.