Where
AND
-Infinity
0

Apache AirflowApache Airflow: Task-instance API exposes secrets in deferred trigger kwargs

Risk 40
Severity
6.5
First published (updated )

Apache Apache AirflowApache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key

Risk 40
Severity
6.5
First published (updated )

Apache AirflowApache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id}

Risk 40
Severity
6.5
First published (updated )

Apache AirflowApache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target

Risk 24
Severity
4.3
First published (updated )

Apache AirflowApache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pypi/apache-airflowApache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API Response

Risk 40
Severity
6.5
First published (updated )

Apache Apache AirflowApache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path

Risk 40
Severity
6.5
First published (updated )

pypi/apache-airflowApache Airflow: Event Log detail endpoint bypasses DAG-scoped event log permission filter

Risk 24
Severity
4.3
First published (updated )

Apache AirflowApache Airflow: Variable masker depth-limit bypass returns cleartext nested secrets

Risk 40
Severity
6.5
First published (updated )

Apache AirflowApache Airflow: Rendered template truncation bypasses nested sensitive-key masking

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache Apache AirflowApache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxy

Risk 37
Severity
5.9
First published (updated )

Apache Apache AirflowApache Airflow: No certificate validation on SMTP STARTTLS connections

Risk 37
Severity
5.9
First published (updated )

Apache AirflowApache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints

Risk 24
Severity
4.3
First published (updated )

pypi/apache-airflowApache Airflow: Arbitrary File Read via Log Symlink following in FileTaskHandler

Risk 40
Severity
6.5
First published (updated )

pypi/apache-airflow-providers-smtpApache Airflow Providers SMTP: No certificate validation on SMTP STARTTLS connections in SMTP provider

Risk 37
Severity
5.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache AirflowApache Airflow: Dags endpoint might provide access to otherwise inaccessible entities

Risk 24
Severity
4.3
First published (updated )

Apache AirflowApache Airflow: Assets graph view bypasses DAG level access control displaying unrelated topologies and all DAGs names to unauthorized users

Risk 24
Severity
4.3
First published (updated )

Apache AirflowApache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

Risk 40
Severity
6.5
First published (updated )

Apache Apache AirflowApache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)

Risk 40
Severity
6.5
First published (updated )

Apache AirflowApache Airflow: DAG authorization bypass

Risk 24
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pypi/apache-airflowApache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli

Risk 40
Severity
6.5
First published (updated )

Apache AirflowApache Airflow: Airflow externalLogUrl Permission Bypass

Risk 28
Severity
6.5
EPSS
0.01%
First published (updated )

Apache AirflowApache Airflow: Assigning single DAG permission leaked all DAGs Import Errors

Risk 28
Severity
6.5
EPSS
0.04%
First published (updated )

Apache AirflowApache Airflow: Disclosure of secrets to UI via kwargs

Risk 40
Severity
6.5
First published (updated )

Apache AirflowApache Airflow: Secrets in rendered templates not redacted properly and exposed in the UI

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache AirflowApache Airflow: Airflow 3 API: /api/v2/dagReports executes DAG Python in API

Risk 37
Severity
5.4
First published (updated )

Apache AirflowApache Airflow: Command injection in "example_dag_decorator"

Risk 32
Severity
4.6
First published (updated )

pip/apache-airflowApache Airflow: Secrets not masked in UI when sensitive variables are set via Airflow cli

Risk 41
Severity
6.5
First published (updated )

pip/apache-airflowApache Airflow: Stored XSS Vulnerability on provider link

Risk 40
Severity
6.1
First published (updated )

pip/apache-airflowApache Airflow: Cache Control - Storage of Sensitive Data in Browser Cache

Risk 34
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203