Apache

Airflow

162 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 07.07.2026 09:18:12
  • Zuletzt bearbeitet 16.09.2026 15:17:36

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire source f...

  • EPSS 0.39%
  • Veröffentlicht 07.07.2026 09:17:28
  • Zuletzt bearbeitet 16.09.2026 15:17:36

A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of trigger / sen...

  • EPSS 0.41%
  • Veröffentlicht 07.07.2026 09:16:26
  • Zuletzt bearbeitet 16.09.2026 15:17:36

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option na...

  • EPSS 0.37%
  • Veröffentlicht 01.06.2026 09:16:20
  • Zuletzt bearbeitet 21.07.2026 19:10:00

The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly by numeric ID after only the generic Audit Log permission check, while the collection endpoint `GET /api/v2/eventLogs` applied per-...

  • EPSS 0.38%
  • Veröffentlicht 01.06.2026 09:16:20
  • Zuletzt bearbeitet 21.07.2026 19:10:00

A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` did not actually reach the underlying `revoke_token...

  • EPSS 0.19%
  • Veröffentlicht 01.06.2026 09:16:20
  • Zuletzt bearbeitet 21.07.2026 19:10:00

Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote certificate when the deployment used `[email] smtp_starttls=True` without `[email] smtp_ssl`. An attack...

  • EPSS 0.49%
  • Veröffentlicht 01.06.2026 09:16:20
  • Zuletzt bearbeitet 21.07.2026 19:10:00

A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kub...

  • EPSS 0.35%
  • Veröffentlicht 01.06.2026 09:16:19
  • Zuletzt bearbeitet 21.07.2026 19:10:00

A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_key` keys inside a JSON template structure) to be bypassed when the rendered field exceeded `[core] max...

  • EPSS 0.68%
  • Veröffentlicht 01.06.2026 09:16:19
  • Zuletzt bearbeitet 21.07.2026 19:10:00

Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary class paths drawn from DAG-author-controlled serialized state without an allowlist or plugin-registry gat...

  • EPSS 0.36%
  • Veröffentlicht 01.06.2026 09:16:19
  • Zuletzt bearbeitet 21.07.2026 19:10:00

Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log server authorized JWT tokens against Dag IDs by applying Python's `str.lstrip()` to the ...