CVE-2026-67587
- EPSS 0.61%
- Veröffentlicht 12.08.2026 15:32:10
- Zuletzt bearbeitet 16.09.2026 15:17:41
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_des...
CVE-2026-65017
- EPSS 0.27%
- Veröffentlicht 12.08.2026 15:31:26
- Zuletzt bearbeitet 16.09.2026 15:17:40
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read acces...
CVE-2026-68968
- EPSS 0.15%
- Veröffentlicht 12.08.2026 15:27:46
- Zuletzt bearbeitet 16.09.2026 15:17:41
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `N...
CVE-2026-68969
- EPSS 0.15%
- Veröffentlicht 12.08.2026 15:26:40
- Zuletzt bearbeitet 16.09.2026 15:17:42
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only ...
CVE-2026-68970
- EPSS 0.17%
- Veröffentlicht 12.08.2026 15:24:53
- Zuletzt bearbeitet 16.09.2026 15:17:42
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value wa...
CVE-2026-68971
- EPSS 0.15%
- Veröffentlicht 12.08.2026 15:24:10
- Zuletzt bearbeitet 16.09.2026 15:17:42
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware ...
CVE-2026-68076
- EPSS 0.22%
- Veröffentlicht 12.08.2026 15:23:22
- Zuletzt bearbeitet 16.09.2026 16:17:14
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name con...
CVE-2026-33264
- EPSS 0.99%
- Veröffentlicht 07.07.2026 09:20:18
- Zuletzt bearbeitet 08.07.2026 19:37:10
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code ...
CVE-2026-49487
- EPSS 0.41%
- Veröffentlicht 07.07.2026 09:19:36
- Zuletzt bearbeitet 16.09.2026 15:17:37
In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, any authentica...
CVE-2026-48828
- EPSS 0.41%
- Veröffentlicht 07.07.2026 09:18:53
- Zuletzt bearbeitet 16.09.2026 15:17:35
The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fir...