Known Vulnerabilities for Airflow by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Airflow" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-97636 json | Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-control... | Not Provided | 2026-09-24 | 2026-09-25 |
| CVE-2026-86843 json | The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-86792 json | Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-86473 json | Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs ... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-86466 json | Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-86465 json | Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key.... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-86462 json | Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that u... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-82355 json | When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow r... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-82311 json | Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despi... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-82310 json | Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Pas... | Not Provided | 2026-09-16 | 2026-09-17 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Airflow | 2.0.1 | |||
| Application | Apache | Airflow | 2.0.0 | |||
| Application | Apache | Airflow | 1.9.0 | |||
| Application | Apache | Airflow | 1.9.0 | |||
| Application | Apache | Airflow | 1.9.0 | |||
| Application | Apache | Airflow | 1.9.0 | |||
| Application | Apache | Airflow | 1.9.0 | |||
| Application | Apache | Airflow | 1.9.0 | |||
| Application | Apache | Airflow | 1.9.0 | |||
| Application | Apache | Airflow | 1.9.0 | |||
| Application | Apache | Airflow | 1.9.0 | |||
| Application | Apache | Airflow | 1.9.0 | |||
| Application | Apache | Airflow | 1.9.0 | |||
| Application | Apache | Airflow | 1.8.2 | |||
| Application | Apache | Airflow | 1.8.2 | |||
| Application | Apache | Airflow | 1.8.2 | |||
| Application | Apache | Airflow | 1.8.2 | |||
| Application | Apache | Airflow | 1.8.2 | |||
| Application | Apache | Airflow | 1.8.1 | |||
| Application | Apache | Airflow | 1.8.0 |