Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2358
  • PyPI/apache-airflow-core
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args 13 Jul
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-2359
  • PyPI/apache-airflow-core
Apache Airflow allows code execution through crafted XCom payloads 13 Jul
  • Fix available
  • Severity - 7.2 (High)
PYSEC-2026-2361
  • PyPI/apache-airflow-core
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false 13 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2360
  • PyPI/apache-airflow-core
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions 13 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-2362
  • PyPI/apache-airflow-core
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries 13 Jul
  • Fix available
  • Severity - 3.7 (Low)
GHSA-5j6p-jrrm-6x94
  • PyPI/apache-airflow-core
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args 01 Jun
  • Fix available
  • Severity - 8.8 (High)
GHSA-6ffj-2wg2-w45j
  • PyPI/apache-airflow-core
Apache Airflow allows code execution through crafted XCom payloads 18 Apr
  • Fix available
  • Severity - 7.2 (High)
GHSA-h97w-pm3w-mwmc
  • PyPI/apache-airflow-core
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions 18 Apr
  • Fix available
  • Severity - 7.5 (High)
GHSA-w7cf-2pmc-5m4c
  • PyPI/apache-airflow-core
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false 18 Apr
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-w9r4-94fj-xp69
  • PyPI/apache-airflow
  • PyPI/apache-airflow-core
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries 18 Apr
  • Fix available
  • Severity - 3.7 (Low)