CVE-2026-40961
- EPSS 0.65%
- Veröffentlicht 01.06.2026 09:16:18
- Zuletzt bearbeitet 21.07.2026 19:10:00
A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirection from a trusted Airflow domain to an attacker-controlled origin. Users are advised to upgrade to ...
CVE-2026-40963
- EPSS 0.48%
- Veröffentlicht 01.06.2026 09:16:18
- Zuletzt bearbeitet 21.07.2026 19:10:00
The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags. An authenticated UI/API user authorized for one Dag could enumerate l...
CVE-2026-41014
- EPSS 0.37%
- Veröffentlicht 01.06.2026 09:16:18
- Zuletzt bearbeitet 21.07.2026 19:10:00
The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate partition run state, schedule configuration, and ...
CVE-2026-41017
- EPSS 0.35%
- Veröffentlicht 01.06.2026 09:16:18
- Zuletzt bearbeitet 21.07.2026 19:10:00
Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy (e.g. nginx / Envoy / a managed load balancer that terminates TLS and f...
CVE-2026-41084
- EPSS 0.48%
- Veröffentlicht 01.06.2026 09:16:18
- Zuletzt bearbeitet 21.07.2026 19:10:00
A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization against the `dag_id` resolved from the URL path while operating on the `dag_id` / `dag_run_id` extract...
CVE-2026-42252
- EPSS 0.38%
- Veröffentlicht 01.06.2026 09:16:18
- Zuletzt bearbeitet 21.07.2026 19:10:00
Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization wa...
CVE-2026-42358
- EPSS 0.35%
- Veröffentlicht 01.06.2026 09:16:18
- Zuletzt bearbeitet 21.07.2026 19:10:00
A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `secret`, `api_key`) to be bypassed when the JSON value's nesting depth exceeded the shared secrets maske...
CVE-2026-42359
- EPSS 0.57%
- Veröffentlicht 01.06.2026 09:16:18
- Zuletzt bearbeitet 21.07.2026 19:10:00
A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a Dag to set XCom entries under reserved key names (e.g. `return_value`) that the matching POST endpoin...
CVE-2026-40861
- EPSS 0.69%
- Veröffentlicht 01.06.2026 09:16:17
- Zuletzt bearbeitet 21.07.2026 19:10:00
A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process (read-path attack — e.g. `/etc/passwd` or `airflow.cfg`) or (b) supply a `task_id` containing `..` sequen...
CVE-2026-45192
- EPSS 0.43%
- Veröffentlicht 01.06.2026 06:51:41
- Zuletzt bearbeitet 21.07.2026 18:10:00
A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission to retrieve secrets stored in a Connection's `extra` JSON blob under field names not prese...