Apache Airflow

6 known vulnerabilities in Apache Airflow, 2 critical, 2 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2020-13927 CVSS 9.8 critical · actively exploited Apache Airflow's Experimental API Authentication Bypass
  • CVE-2020-11978 CVSS 8.8 high · actively exploited Apache Airflow Command Injection

Latest vulnerabilities

  • CVE-2026-86473 CVSS 9.1 critical Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out…
  • CVE-2026-82355 CVSS 4.2 medium When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the…
  • CVE-2026-75158 CVSS 4.3 medium Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags…
  • CVE-2026-75157 CVSS 7.5 high Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any…
  • CVE-2020-13927 CVSS 9.8 critical · actively exploited Apache Airflow's Experimental API Authentication Bypass
  • CVE-2020-11978 CVSS 8.8 high · actively exploited Apache Airflow Command Injection