Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2365
  • PyPI/apache-airflow-providers-cncf-kubernetes
Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments 13 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-1144
  • PyPI/apache-airflow-providers-cncf-kubernetes
Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service 07 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-1143
  • PyPI/apache-airflow-providers-cncf-kubernetes
Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration 07 Jul
  • Fix available
  • Severity - 7.2 (High)
GHSA-524w-vq63-2xhf
  • PyPI/apache-airflow-providers-cncf-kubernetes
Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments 19 May
  • Fix available
  • Severity - 8.7 (High)
GHSA-mg2x-mggj-6955
  • PyPI/apache-airflow
  • PyPI/apache-airflow-providers-cncf-kubernetes
Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service 24 Jan 2024
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2rx4-9f5h-9gjf
  • PyPI/apache-airflow-providers-cncf-kubernetes
Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration 06 Jul 2023
  • Fix available
  • Severity - 7.2 (High)