Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3990
  • PyPI/apache-airflow
See record for full details 21 Sep
  • Fix available
  • Severity - 9.1 (Critical)
PYSEC-2026-3989
  • PyPI/apache-airflow
See record for full details 21 Sep
  • No fix available
  • Severity - 4.2 (Medium)
PYSEC-2026-3988
  • PyPI/apache-airflow
See record for full details 21 Sep
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-3986
  • PyPI/apache-airflow-providers-apache-kafka
See record for full details 16 Sep
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-3806
  • PyPI/apache-airflow
Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API 10 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-5247-m8w9-2v4m
  • PyPI/apache-airflow
Apache Airflow missing team context permits cross-team Dag actions and XCom reads 12 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-cjv4-7hp2-2x9h
  • PyPI/apache-airflow
Apache Airflow bulk endpoints log Variable and Connection secrets in cleartext 12 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-f3c2-j7g8-vpp8
  • PyPI/apache-airflow
Apache Airflow Task SDK fails to mask list-shaped JSON Variables 12 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2qjv-p2gc-mjg2
  • PyPI/apache-airflow
Apache Airflow Task SDK Callback deserialization can import arbitrary modules in the scheduler 12 Aug
  • Fix available
  • Severity - 8.8 (High)
GHSA-75mg-c62r-v95g
  • PyPI/apache-airflow
Apache Airflow environment-variable secrets backend permits cross-team credential use 12 Aug
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-c56v-8w4g-3mfm
  • PyPI/apache-airflow
Apache Airflow Config API exposes team-scoped sensitive configuration values 12 Aug
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-fcmm-42r9-mmmm
  • PyPI/apache-airflow
Apache Airflow XCom API permits unsafe deserialization through JSON string literals 12 Aug
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-g4qj-5vxv-wggf
  • PyPI/apache-airflow
Apache Airflow Variables UI fails to mask sensitive values in deeply nested iterables 12 Aug
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-j4jc-cq9h-xrhr
  • PyPI/apache-airflow
Apache Airflow Backfill API parser discrepancy permits cross-DAG authorization bypass 12 Aug
  • Fix available
  • Severity - 7.5 (High)
GHSA-q4c3-7575-55j2
  • PyPI/apache-airflow
Apache Airflow scheduler unsafely deserializes human-in-the-loop task next_kwargs 12 Aug
  • Fix available
  • Severity - 7.3 (High)
GHSA-8prw-8m6x-8w6f
  • PyPI/apache-airflow
Apache Airflow exception-node deserialization permits arbitrary callable execution 12 Aug
  • Fix available
  • Severity - 8.8 (High)