from 0, < 1.10.11
HIGH8.8CVE-2020-11978⚠ KEVRemote code execution (RCE) in Apache Airflow from 0, < 1.10.11
CRITICAL9.8Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize()
from 0, < 3.3.0
CRITICAL9.8Apache Airflow: Privilege escalation using airflow logs
from 0, < 2.6.0
CRITICAL9.8Session Fixation
>= 2.2.4, < 2.3.4
CRITICAL9.8Apache Airflow: Variable Import endpoint missed authentication check
>= 2.0.0, < 2.1.3
CRITICAL9.8Command injection via Celery broker in Apache Airflow
from 0, < 1.10.11
CRITICAL9.8Insecure default config of Celery worker in Apache Airflow
from 0, < 1.10.11
HIGH8.8Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
from 0, < 3.2.2
HIGH8.8Apache Airflow: Bad example of BashOperator shell injection via dag_run.conf
from 0, < 3.2.0
HIGH8.8Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API
>= 3.1.8, < 3.2.0
HIGH8.8Apache Airflow: Authenticated DAG authors could execute code on scheduler nodes
from 0, < 2.10.1
HIGH8.8Apache Airflow: Command Injection in an example DAG
>= 2.10.0, < 2.10.1
HIGH8.8Apache Airflow: DAG Author Code Execution possibility in airflow-scheduler
>= 2.4.0, < 2.9.3
HIGH8.8Apache Airflow: Airflow "Run task" feature allows execution with unnecessary priviledges
from 0, < 2.6.0
HIGH8.8Apache Airflow <2.4.0 has an RCE in a bash example
from 0, < 2.4.0
HIGH8.8Apache Airflow: RCE in example DAGs
from 0, < 2.2.4
HIGH8.4Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information
from 0, < 2.11.1
HIGH8.1Apache Airflow: RCE by race condition in example_xcom dag
from 0, < 3.2.0
HIGH8.1Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization
>= 3.1.0, < 3.1.8
HIGH8.1Apache Airflow: Ignored Airflow Permissions
>= 2.8.0, < 2.8.3
HIGH8.1Apache Airflow: Exposure of sensitive connection information, DOS and SSRF on "test connection" feature
from 0, < 2.7.0
HIGH8.1Session still functional after user is deactivated
from 0, < 2.4.2
HIGH8.0Session fixation in Apache Airflow web interface
from 0, < 2.7.1
HIGH7.8Apache Airflow Hive Provider vulnerability (command injection via hive_cli connection)
from 0, < 2.3.0
HIGH7.7Incorrect Session Validation in Apache Airflow
from 0, < 1.10.14
HIGH7.5Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to
>= 3.0.0, < 3.2.0
HIGH7.5Apache Airflow: JWT token appearing in logs
>= 3.0.0, < 3.2.0
HIGH7.5Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI
>= 3.0.0, < 3.2.0
HIGH7.5Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications
>= 3.0.0, < 3.1.8
HIGH7.5Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata
>= 3.0.0, < 3.1.8
HIGH7.5Apache Airflow: Secrets in rendered templates could contain parts of sensitive values when truncated
>= 3.1.0, < 3.1.6
HIGH7.5Apache Airflow: proxy credentials for various providers might leak in task logs
from 0, < 3.1.6
HIGH7.5Apache Airflow: Sensitive configuration values are not masked in the logs by default
from 0, < 2.10.3
HIGH7.5Apache Airflow: Potential pickle deserialization vulnerability in XComs
from 0, < 2.8.1
HIGH7.5Apache Airflow Celery provider, Apache Airflow: Sensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend
>= 1.10.0, < 2.7.0
HIGH7.5Apache Airflow prior to 2.3.1 may include sensitive values in rendered template
from 0, < 2.3.1
HIGH7.5Format String Vulnerability
>= 2.3.0, < 2.3.5
HIGH7.2Apache Airflow: Open Redirect Bypass Vulnerability
>= 3.0.0, < 3.2.2
HIGH7.2Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5)
from 0, < 3.2.0
MEDIUM6.5Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key
from 0, < 3.3.0
MEDIUM6.5Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs
from 0, < 3.3.0
MEDIUM6.5Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id}
from 0, < 3.3.0
MEDIUM6.5Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options
from 0, < 3.3.0
MEDIUM6.5Apache Airflow: Variable masker depth-limit bypass returns cleartext nested secrets
from 0, < 3.2.2
MEDIUM6.5Apache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
from 0, < 3.1.8
MEDIUM6.5Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)
>= 3.0.0, < 3.2.0
MEDIUM6.5Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli
from 0, < 2.11.1
MEDIUM6.5Apache Airflow: Disclosure of secrets to UI via kwargs
from 0, < 2.11.1, >= 3.0.0, < 3.1.4
MEDIUM6.5Apache Airflow: Airflow externalLogUrl Permission Bypass
>= 3.1.0, < 3.1.7
MEDIUM6.5Apache Airflow: Assigning single DAG permission leaked all DAGs Import Errors
from 0, < 3.1.7
MEDIUM6.5Apache Airflow: Secrets in rendered templates not redacted properly and exposed in the UI
>= 3.1.0, < 3.1.4
MEDIUM6.5Apache Airflow: Connection sensitive details exposed to users with READ permissions
>= 3.0.3, < 3.0.4
MEDIUM6.5Apache Airflow: Bypass permission verification to read code of other dags
from 0, < 2.8.1
MEDIUM6.5Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service
>= 2.3.0, < 2.6.1
MEDIUM6.5Apache Airflow: Missing CSRF protection on DAG/trigger
>= 2.7.0, < 2.7.4
MEDIUM6.5Apache Airflow: Improper access control vulnerability on the "varimport" endpoint
from 0, < 2.8.0
MEDIUM6.5Apache Airflow: Permission verification bypass allows viewing dagruns of other dags
from 0, < 2.7.3
MEDIUM6.5Apache Airflow: Bypass permission verification to view task instances of other dags
from 0, < 2.7.2
MEDIUM6.5Apache Airflow: Improper access control vulnerability in the "List dag warnings" feature
from 0, < 2.7.2
MEDIUM6.5Apache Airflow: Improper access control to DAG resources
from 0, < 2.7.2
MEDIUM6.5Apache Airflow: Secrets can be unmasked in the "Rendered Template"
from 0, < 2.7.1
MEDIUM6.5Apache Airflow path traversal by authenticated user
from 0, < 2.6.3
MEDIUM6.5Apache Airflow: Scheduler remote DoS
from 0, < 2.6.3
MEDIUM6.5Apache Airflow: Access to DAGs without relevant permission
from 0, < 2.6.3
MEDIUM6.5Apache Airflow: ReDoS via dags function
from 0, < 2.6.3
MEDIUM6.5Apache Airflow: Security vulnerability on AirFlow Connections
from 0, < 2.6.3
MEDIUM6.5Apache Airflow: Information disclosure on configuration view
>= 2.5.0, < 2.6.2
MEDIUM6.5Apache Airflow: Creating DagRuns didn't respect Dag-level permissions in the Webserver
>= 2.0.0, < 2.2.0
MEDIUM6.5CWE-284 Improper Access Control on Configurations Endpoint for the Stable API
>= 2.0.0, < 2.0.1
MEDIUM6.1Apache Airflow: Stored XSS Vulnerability on provider link
from 0, < 2.10.0
MEDIUM6.1Apache Airflow: Open redirect during login
from 0, < 2.4.3
MEDIUM6.1Apache Airflow prior to 2.4.2 allows reflected XSS via Origin Query Argument in URL
from 0, < 2.4.2
MEDIUM6.1Apache Airflow prior to 2.4.2 has an open redirect
from 0, < 2.4.2
MEDIUM6.1Open Redirect
>= 2.3.0, < 2.3.5
MEDIUM6.1Apache Airflow: Reflected XSS via Origin Query Argument in URL
from 0, < 2.2.4
MEDIUM6.1Apache Airflow Reflected XSS via Origin Query Argument in URL
>= 1.0.0, < 1.10.15, >= 2.0.0, < 2.0.2
MEDIUM6.1Apache Airflow Cross-site Scripting
from 0, < 1.10.15, >= 2.0.0, < 2.0.2
MEDIUM6.1Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944
from 0, < 1.10.15, >= 2.0.0, < 2.0.2
MEDIUM6.1Stored XSS in Apache Airflow
from 0, < 1.10.11
MEDIUM5.9Apache Airflow: No certificate validation on SMTP STARTTLS connections
>= 2.0.0, < 3.2.2
MEDIUM5.9Apache Airflow: Dag Code and Import Error Permissions Ignored
from 0, < 2.8.2
MEDIUM5.9Apache Airflow SMTP Provider, Apache Airflow IMAP Provider, Apache Airflow: SMTP/IMAP client components allowed MITM due to missing Certificate Validation
from 0, < 2.7.0
MEDIUM5.5Apache Airflow: Cache Control - Storage of Sensitive Data in Browser Cache
from 0, < 2.9.2
MEDIUM5.5Apache Airflow Spark Provider RCE that bypass restrictions to read arbitrary files
from 0, < 2.3.0
MEDIUM5.4Apache Airflow: Airflow 3 API: /api/v2/dagReports executes DAG Python in API
>= 3.0.0, < 3.1.1
MEDIUM5.4Apache Airflow: Potential XSS Vulnerability
from 0, < 2.9.3
MEDIUM5.4Apache Airflow: XSS vulnerability in Task Instance Log/Log Details
>= 2.9.0, < 2.9.1
MEDIUM5.4Apache Airflow: DAG Params alllow to embed unchecked Javascript
>= 2.6.0, < 2.7.4
MEDIUM5.4Stored XSS on Apache Airflow
from 0, < 2.6.0
MEDIUM5.4Multiple stored XSS in RBAC Admin screens in Apache Airflow
from 0, < 1.10.11
MEDIUM5.3Apache Airflow: Exposing stack trace in case of constraint error
from 0, < 3.2.0
MEDIUM5.3Apache Airflow: Potentially harmful permission changing by log task handler
>= 2.8.2, < 2.8.4
MEDIUM5.3Information disclosure in Apache Airflow
from 0, < 2.5.2
MEDIUM5.3No Authentication on Logging Server
from 0, < 2.1.2
MEDIUM5.3Apache Airflow: Lineage API endpoint for Experimental API missed authentication check
>= 2.0.0, < 2.0.1
MEDIUM5.3SSRF vulnerability in Apache Airflow
from 0, < 1.10.13
MEDIUM4.9Apache Airflow: Secrets not masked in UI when sensitive variables are set via Airflow cli
from 0, < 2.10.3
MEDIUM4.7Apache Airflow: Overly broad default permissions for Viewer/Ops (audit logs)
from 0, < 2.8.2
MEDIUM4.7Overly permissive umask for daemons
from 0, < 2.3.4
MEDIUM4.6Apache Airflow: Command injection in "example_dag_decorator"
>= 3.0.0, < 3.0.5
MEDIUM4.6Apache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables)
>= 3.0.0, < 3.1.1
MEDIUM4.3Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target
from 0, < 3.3.0
MEDIUM4.3Apache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permission filter
from 0, < 3.2.2
MEDIUM4.3Apache Airflow: Dags endpoint might provide access to otherwise inaccessible entities
from 0, < 3.2.1
MEDIUM4.3Apache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users
from 0, < 3.2.1
MEDIUM4.3Apache Airflow: DAG authorization bypass
>= 3.0.0, < 3.1.8
MEDIUM4.3Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
>= 2.7.0, < 2.9.0
MEDIUM4.3Apache Airflow: Improper access control to DAG resources
from 0, < 2.8.0
MEDIUM4.3Apache Airflow missing fix for CVE-2023-40611 in 2.7.1 (DAG run broken access)
from 0, < 2.7.3
MEDIUM4.3Apache Airflow: Sensitive parameters exposed in API when "non-sensitive-only" configuration is set
>= 2.4.0, < 2.7.0
MEDIUM4.3Apache Airflow: Configuration information leakage vulnerability
>= 2.7.0, < 2.7.2
MEDIUM4.3Apache Airflow Dag Runs Broken Access Control Vulnerability
from 0, < 2.7.3
LOW3.7Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
>= 3.0.0, < 3.2.0
LOW3.1Apache Airflow: DAG authorization bypass on /ui/structure/structure_data
>= 3.0.0, < 3.2.2
LOW2.8Apache Airflow logs passwords in plaintext
from 0, < 1.10.13