Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
PyPI/apache-airflow-core — 5 CVEs · VulnScope
pkg:PyPI/
apache-airflow-core
5 total CVEs
HIGH
6
MEDIUM
2
LOW
2
✅ Check your installed version
Check
All known vulnerabilities
HIGH
8.8
CVE-2026-49298
Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
from 0, < 3.2.2
HIGH
8.8
CVE-2026-49298
Apache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
from 0, < 3.2.2
HIGH
7.5
CVE-2026-32228
Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to
>= 3.0.0, < 3.2.0
HIGH
7.5
Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to
>= 3.0.0, < 3.2.0
HIGH
7.2
Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5)
from 0, < 3.2.0
HIGH
7.2
Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5)
from 0, < 3.2.0
MEDIUM
5.3
Apache Airflow: Exposing stack trace in case of constraint error
from 0, < 3.2.0
MEDIUM
5.3
Apache Airflow: Exposing stack trace in case of constraint error
from 0, < 3.2.0
LOW
3.7
Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
>= 3.0.0, < 3.2.0
LOW
3.7
Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
>= 3.0.0, < 3.2.0
CVE-2026-32228
CVE-2026-25917
CVE-2026-25917
CVE-2026-30912
CVE-2026-30912
CVE-2026-32690
CVE-2026-32690