Junglewise Threat Intelligence

CVE-2026-28563: Apache Airflow authorization bypass in DAG dependencies endpoint

CVE-2026-28563 · Severity: medium · CVSS 4.3 · Published 2026-03-17

Technologies: Apache Airflow, apache-airflow (PyPI). Vendors: Apache, PyPI.

Executive brief

Apache Airflow, a platform used to programmatically author and monitor workflows, contains a security flaw in its user interface. An authenticated user with limited permissions can view the entire dependency graph of all workflows (DAGs) in the system, even those they are not authorized to see. This could lead to the exposure of sensitive internal process names and organizational workflow structures.

Technical details

An authorization bypass exists in Apache Airflow versions 3.1.0 through 3.1.7 within the `/ui/dependencies` endpoint. The root cause is a failure to apply DAG-level authorization filters when returning the dependency graph. An authenticated attacker with 'DAG Dependencies' permissions can exploit this via a network request to the affected endpoint to retrieve a full list of DAG IDs and their relationships, bypassing intended access controls (CWE-732). The issue is resolved in version 3.1.8 by implementing proper readable DAG checks in the FastAPI route.

Affected products

  • Apache Airflow >= 3.0.0, < 3.1.8

Timeline

  • 2026-02-16: other: Remediation pull request submitted
  • 2026-03-17: disclosed: Vulnerability disclosed via oss-security and GitHub Advisory Database
  • 2026-03-17: patched: Version 3.1.8 released

References

Related threats