Known Vulnerabilities for Apache Airflow by Apache Software Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Apache Airflow" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86792 json | Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-86466 json | Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-86465 json | Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key.... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-86462 json | Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that u... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-82311 json | Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despi... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-82310 json | Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Pas... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-76187 json | Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential ... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-76186 json | Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow ... | Not Provided | 2026-09-16 | 2026-09-16 |
| CVE-2026-75156 json | Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s durin... | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-68971 json | Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `... | Not Provided | 2026-08-12 | 2026-08-13 |