apache-airflow
Programmatically author, schedule and monitor data pipelines
Security Advisories for apache-airflow in pypi
Moderate
about 1 month ago
apache-airflow DAG source authorization bypass exposes co-located DAG source
pypi
apache-airflow
Moderate
3 months ago
Apache Airflow has no certificate validation on SMTP STARTTLS connections
pypi
apache-airflow
Moderate
3 months ago
Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout
pypi
apache-airflow
Moderate
3 months ago
Apache Airflow has an Authorization Bypass Through User-Controlled Key
pypi
apache-airflow
High
3 months ago
Apache Airflow has a Deserialization of Untrusted Data vulnerability
pypi
apache-airflow
High
3 months ago
Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key
pypi
apache-airflow
Critical
3 months ago
Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
pypi
apache-airflow
High
3 months ago
Apache Airflow Vulnerable to Deserialization of Untrusted Data
pypi
apache-airflow
Moderate
3 months ago
Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
pypi
apache-airflow
Moderate
3 months ago
Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
pypi
apache-airflow
High
3 months ago
Apache Airflow: Authenticated users can bypass the `is_safe_url` check
pypi
apache-airflow
Moderate
3 months ago
Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
pypi
apache-airflow
Moderate
3 months ago
Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra` to read-permitted users
pypi
apache-airflow
Moderate
4 months ago
Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record
pypi
apache-airflow
Moderate
4 months ago
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
pypi
apache-airflow
Moderate
4 months ago
Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
pypi
apache-airflow
High
4 months ago
Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API
pypi
apache-airflow
Moderate
4 months ago
Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI
pypi
apache-airflow
Moderate
4 months ago
Apache Airflow has an authorization bypass in DagRun wait endpoint
pypi
apache-airflow
Moderate
5 months ago
Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange
pypi
apache-airflow
High
5 months ago
Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications
pypi
apache-airflow
High
5 months ago
Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization
pypi
apache-airflow
High
5 months ago
Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata
pypi
apache-airflow
Moderate
6 months ago
Apache Airflow exposes sensitive information in its log files
pypi
apache-airflow
High
6 months ago
Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
pypi
apache-airflow
Moderate
6 months ago
Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access
pypi
apache-airflow
Moderate
6 months ago
Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users
pypi
apache-airflow
High
7 months ago
Apache Airflow proxy credentials for various providers might leak in task logs
pypi
apache-airflow
High
7 months ago
Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
pypi
apache-airflow
Moderate
8 months ago
Apache Airflow exposes secret values to authenticated UI users via rendered templates
pypi
apache-airflow
Moderate
10 months ago
Apache Airflow's create action can upsert existing Pools/Connections/Variables
pypi
apache-airflow
Moderate
10 months ago
Apache Airflow `/api/v2/dagReports` executes DAG Python in API
pypi
apache-airflow
Moderate
10 months ago
Apache Airflow has a command injection vulnerability in "example_dag_decorator"
pypi
apache-airflow
Moderate
11 months ago
Apache Airflow: Connection sensitive details exposed to users with READ permissions
pypi
apache-airflow
Potential
High
over 1 year ago
Apache Airflow Common SQL Provider Vulnerable to SQL Injection
pypi
apache-airflow-providers-common-sql
Potential
Moderate
over 1 year ago
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
pypi
apache-airflow-providers-mysql
Low
almost 2 years ago
Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
pypi
apache-airflow
High
almost 2 years ago
Apache Airflow vulnerable to Execution with Unnecessary Privileges
pypi
apache-airflow
High
almost 2 years ago
Apache Airflow vulnerable to Improper Encoding or Escaping of Output
pypi
apache-airflow
Potential
Low
about 2 years ago
Apache Airflow Providers FAB Insufficient Session Expiration vulnerability
pypi
apache-airflow-providers-fab
High
about 2 years ago
Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
pypi
apache-airflow
Moderate
about 2 years ago
Apache Airflow Potential Cross-site Scripting Vulnerability
pypi
apache-airflow
Low
about 2 years ago
Apache Airflow does not return the "Cache-Control" header for dynamic content
pypi
apache-airflow
Moderate
over 2 years ago
Apache Airflow: XSS vulnerability in Task Instance Log/Log Details
pypi
apache-airflow
Potential
Low
over 2 years ago
Improper Certificate Validation vulnerability in Apache Airflow FTP Provider
pypi
apache-airflow-providers-ftp
Moderate
over 2 years ago
Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
pypi
apache-airflow
Moderate
over 2 years ago
Apache Airflow Improper Preservation of Permissions vulnerability
pypi
apache-airflow
Moderate
over 2 years ago
Apache Airflow: Incorrect Default Permissions in audit logs for Ops and Viewers users
pypi
apache-airflow
Moderate
over 2 years ago
Apache Airflow: DAG Code and Import Error Permissions Ignored
pypi
apache-airflow
Potential
Critical
over 2 years ago
Improper Certificate Validation in apache airflow mongo hook
pypi
apache-airflow-providers-mongo
Moderate
over 2 years ago
Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service
pypi
apache-airflow-providers-cncf-kubernetes, apache-airflow
High
over 2 years ago
Apache Airflow: Bypass permission verification to read code of other dags
pypi
apache-airflow
High
over 2 years ago
Apache Airflow: pickle deserialization vulnerability in XComs
pypi
apache-airflow
Moderate
over 2 years ago
Apache Airflow Cross-Site Request Forgery vulnerability
pypi
apache-airflow
Moderate
over 2 years ago
Apache Airflow vulnerable to Exposure of Resource to Wrong Sphere
pypi
apache-airflow
Moderate
over 2 years ago
Apache Airflow has a stored cross-site scripting vulnerability
pypi
apache-airflow
High
almost 3 years ago
Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
pypi
apache-airflow
Moderate
almost 3 years ago
Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes
pypi
apache-airflow
High
almost 3 years ago
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
pypi
apache-airflow, apache-airflow-providers-celery
Moderate
almost 3 years ago
Apache Airflow vulnerable to Exposure of Sensitive Information
pypi
apache-airflow
Moderate
almost 3 years ago
Apache Airflow vulnerable to sensitive information exposure when users list warnings for all DAGs
pypi
apache-airflow
Moderate
almost 3 years ago
Apache Airflow vulnerable to sensitive information exposure when expose-config is set to non-sensitive-only
pypi
apache-airflow
Moderate
almost 3 years ago
Apache Airflow vulnerable to sensitive information exposure
pypi
apache-airflow
Potential
High
almost 3 years ago
Apache HDFS Provider error message suggested
pypi
apache-airflow-providers-apache-hdfs
Moderate
almost 3 years ago
Apache Airflow Incorrect Authorization vulnerability
pypi
apache-airflow
Potential
High
almost 3 years ago
Apache Airflow vulnerable arbitrary code execution via Spark server
pypi
apache-airflow-providers-apache-spark
Potential
High
almost 3 years ago
Airflow Sqoop Provider RCE Vulnerability
pypi
apache-airflow-providers-apache-sqoop
Moderate
almost 3 years ago
Apache Airflow missing Certificate Validation
pypi
apache-airflow, apache-airflow-providers-imap, apache-airflow-providers-smtp
Potential
High
about 3 years ago
apache-airflow-providers-apache-drill Improper Input Validation vulnerability
pypi
apache-airflow-providers-apache-drill
Potential
Critical
about 3 years ago
Apache Airflow Hive Provider Beeline remote code execution with Principal
pypi
apache-airflow-providers-apache-hive
Potential
High
about 3 years ago
Apache Airflow ODBC Provider Argument Injection vulnerability
pypi
apache-airflow-providers-odbc
Potential
Moderate
about 3 years ago
Apache Airflow ODBC Provider, Apache Airflow MSSQL Provider Improper Input Validation vulnerability
pypi
apache-airflow-providers-odbc
High
about 3 years ago
Apache Airflow vulnerable to exposure of sensitive information
pypi
apache-airflow
Critical
over 3 years ago
Apache Airflow vulnerable to Privilege Context Switching Error
pypi
apache-airflow
Moderate
over 3 years ago
Apache Airflow vulnerable to stored Cross-site Scripting
pypi
apache-airflow
Potential
Critical
over 3 years ago
Apache Airflow Hive Provider vulnerable to code injection
pypi
apache-airflow-providers-apache-hive
Potential
High
over 3 years ago
Apache Airflow Spark Provider vulnerable to improper input validation
pypi
apache-airflow-providers-apache-spark
Potential
High
over 3 years ago
Apache Airflow Drill Provider vulnerable to improper input validation
pypi
apache-airflow-providers-apache-drill