Apache Airflow
6 known vulnerabilities in Apache Airflow, 2 critical, 2 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2020-13927 CVSS 9.8 critical · actively exploited Apache Airflow's Experimental API Authentication Bypass
- CVE-2020-11978 CVSS 8.8 high · actively exploited Apache Airflow Command Injection
Latest vulnerabilities
- CVE-2026-86473 CVSS 9.1 critical Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out…
- CVE-2026-82355 CVSS 4.2 medium When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the…
- CVE-2026-75158 CVSS 4.3 medium Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags…
- CVE-2026-75157 CVSS 7.5 high Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any…
- CVE-2020-13927 CVSS 9.8 critical · actively exploited Apache Airflow's Experimental API Authentication Bypass
- CVE-2020-11978 CVSS 8.8 high · actively exploited Apache Airflow Command Injection