CVE-2026-81862
- EPSS 0.28%
- Veröffentlicht 29.09.2026 10:17:12
- Zuletzt bearbeitet 07.10.2026 20:05:46
Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into the `CREATE ...
CVE-2026-86473
- EPSS 0.4%
- Veröffentlicht 21.09.2026 14:33:26
- Zuletzt bearbeitet 25.09.2026 13:53:06
Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but ...
CVE-2026-75158
- EPSS 0.23%
- Veröffentlicht 21.09.2026 14:32:47
- Zuletzt bearbeitet 25.09.2026 13:58:05
Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore enumerate asse...
CVE-2026-82355
- EPSS 0.27%
- Veröffentlicht 21.09.2026 14:32:04
- Zuletzt bearbeitet 25.09.2026 19:43:35
When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over cookie. The...
CVE-2026-75157
- EPSS 0.17%
- Veröffentlicht 18.09.2026 07:51:23
- Zuletzt bearbeitet 22.09.2026 19:16:44
Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently suppressing asse...
CVE-2026-59244
- EPSS 0.11%
- Veröffentlicht 12.08.2026 15:43:17
- Zuletzt bearbeitet 16.09.2026 15:17:39
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `va...
CVE-2026-58076
- EPSS 0.28%
- Veröffentlicht 12.08.2026 15:40:59
- Zuletzt bearbeitet 16.09.2026 15:17:38
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An o...
CVE-2026-59242
- EPSS 0.25%
- Veröffentlicht 12.08.2026 15:35:00
- Zuletzt bearbeitet 16.09.2026 15:17:38
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom wr...
CVE-2026-54183
- EPSS 0.26%
- Veröffentlicht 12.08.2026 15:34:22
- Zuletzt bearbeitet 16.09.2026 15:17:37
Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Varia...
CVE-2026-67260
- EPSS 0.78%
- Veröffentlicht 12.08.2026 15:33:02
- Zuletzt bearbeitet 16.09.2026 15:17:40
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that va...