{"schema_version":1,"title":"Apache Airflow vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 63 vulnerabilities in Apache Airflow: 3 in the last 7 days and 26 in the last 90 days, 7 of them critical and 2 exploited in the wild. The most recent, CVE-2026-86473, was published on 21 September 2026.","url":"https://junglewise.ai/threats/technologies/airflow","json_url":"https://junglewise.ai/threats/technologies/airflow.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/airflow","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":19,"all_time":63,"critical":7,"exploited":2,"last_7_days":3,"last_30_days":6,"last_90_days":26,"last_365_days":54},"latest":[{"cve":"CVE-2026-86473","cvss":9.1,"epss":0.0052,"slug":"cve-2026-86473-apache-airflow-the-core-api-logout-endpoint-revokes-only-a","title":"Apache Airflow Core API logout incomplete token revocation","severity":"critical","exploited":false,"published_at":"2026-09-21T15:17:32.997+00:00","url":"https://junglewise.ai/threats/cve-2026-86473-apache-airflow-the-core-api-logout-endpoint-revokes-only-a"},{"cve":"CVE-2026-82355","cvss":4.2,"epss":0.0031,"slug":"cve-2026-82355-when-a-request-to-the-airflow-core-api-carries-both-a-session","title":"Apache Airflow authentication bypass via session cookie precedence","severity":"medium","exploited":false,"published_at":"2026-09-21T15:17:32.43+00:00","url":"https://junglewise.ai/threats/cve-2026-82355-when-a-request-to-the-airflow-core-api-carries-both-a-session"},{"cve":"CVE-2026-75158","cvss":4.3,"epss":0.0036,"slug":"cve-2026-75158-apache-airflow-s-assets-events-api-returned-asset-events-for","title":"Apache Airflow information disclosure in /assets/events API","severity":"medium","exploited":false,"published_at":"2026-09-21T15:17:31.36+00:00","url":"https://junglewise.ai/threats/cve-2026-75158-apache-airflow-s-assets-events-api-returned-asset-events-for"},{"cve":"CVE-2026-75157","cvss":7.5,"epss":0.0044,"slug":"cve-2026-75157-apache-airflow-privilege-escalation-in-asset-queued-events-delete","title":"Apache Airflow privilege escalation in asset queued-events DELETE","severity":"high","exploited":false,"published_at":"2026-09-18T08:17:01.093+00:00","url":"https://junglewise.ai/threats/cve-2026-75157-apache-airflow-privilege-escalation-in-asset-queued-events-delete"},{"cve":"CVE-2026-82310","cvss":7.2,"epss":0.01,"slug":"cve-2026-82310-apache-airflow-fab-provider-token-revocation-bypass-for","title":"Apache Airflow FAB provider token revocation bypass for deactivated accounts","severity":"high","exploited":false,"published_at":"2026-09-16T10:16:53.307+00:00","url":"https://junglewise.ai/threats/cve-2026-82310-apache-airflow-fab-provider-token-revocation-bypass-for"},{"cve":"CVE-2026-76186","cvss":9.1,"epss":0.0081,"slug":"cve-2026-76186-apache-airflow-keycloak-provider-session-token-binding-bypass","title":"Apache Airflow Keycloak provider session token binding bypass","severity":"critical","exploited":false,"published_at":"2026-09-16T10:16:52.793+00:00","url":"https://junglewise.ai/threats/cve-2026-76186-apache-airflow-keycloak-provider-session-token-binding-bypass"},{"cve":"CVE-2026-68971","cvss":6.5,"epss":0.0059,"slug":"cve-2026-68971-apache-airflow-authorization-bypass-in-asset-materialization-and","title":"Apache Airflow authorization bypass in asset materialization and XCom endpoints","severity":"medium","exploited":false,"published_at":"2026-08-12T16:17:19.97+00:00","url":"https://junglewise.ai/threats/cve-2026-68971-apache-airflow-authorization-bypass-in-asset-materialization-and"},{"cve":"CVE-2026-68970","cvss":6.5,"epss":0.0039,"slug":"cve-2026-68970-apache-airflow-task-sdk-variable-masking-bypass-for-list-shaped","title":"Apache Airflow Task SDK variable masking bypass for list-shaped values","severity":"medium","exploited":false,"published_at":"2026-08-12T16:17:19.853+00:00","url":"https://junglewise.ai/threats/cve-2026-68970-apache-airflow-task-sdk-variable-masking-bypass-for-list-shaped"},{"cve":"CVE-2026-68969","cvss":6.5,"epss":0.0064,"slug":"cve-2026-68969-apache-airflow-information-disclosure-in-audit-logs","title":"Apache Airflow information disclosure in audit logs","severity":"medium","exploited":false,"published_at":"2026-08-12T16:17:19.73+00:00","url":"https://junglewise.ai/threats/cve-2026-68969-apache-airflow-information-disclosure-in-audit-logs"},{"cve":"CVE-2026-68968","cvss":7.5,"epss":0.0075,"slug":"cve-2026-68968-apache-airflow-backfill-api-authorization-bypass-via-type","title":"Apache Airflow Backfill API authorization bypass via type coercion mismatch","severity":"high","exploited":false,"published_at":"2026-08-12T16:17:19.607+00:00","url":"https://junglewise.ai/threats/cve-2026-68968-apache-airflow-backfill-api-authorization-bypass-via-type"},{"cve":"CVE-2026-68076","cvss":5.4,"epss":0.0062,"slug":"cve-2026-68076-apache-airflow-environment-variable-secrets-backend-team-scope","title":"Apache Airflow environment-variable secrets backend team-scope bypass","severity":"medium","exploited":false,"published_at":"2026-08-12T16:17:15.223+00:00","url":"https://junglewise.ai/threats/cve-2026-68076-apache-airflow-environment-variable-secrets-backend-team-scope"},{"cve":"CVE-2026-67587","cvss":8.8,"epss":0.0117,"slug":"cve-2026-67587-apache-airflow-arbitrary-module-import-via-deserialized-callback","title":"Apache Airflow arbitrary module import via deserialized callback","severity":"high","exploited":false,"published_at":"2026-08-12T16:17:15.09+00:00","url":"https://junglewise.ai/threats/cve-2026-67587-apache-airflow-arbitrary-module-import-via-deserialized-callback"},{"cve":"CVE-2026-67260","cvss":7.3,"epss":0.014,"slug":"cve-2026-67260-apache-airflow-unsafe-deserialization-in-awaiting-input-task","title":"Apache Airflow unsafe deserialization in awaiting_input task state","severity":"high","exploited":false,"published_at":"2026-08-12T16:17:14.813+00:00","url":"https://junglewise.ai/threats/cve-2026-67260-apache-airflow-unsafe-deserialization-in-awaiting-input-task"},{"cve":"CVE-2026-65017","cvss":6.5,"epss":0.007,"slug":"cve-2026-65017-apache-airflow-config-api-sensitive-value-masking-bypass-in-multi","title":"Apache Airflow Config API sensitive value masking bypass in multi-team mode","severity":"medium","exploited":false,"published_at":"2026-08-12T16:17:12.577+00:00","url":"https://junglewise.ai/threats/cve-2026-65017-apache-airflow-config-api-sensitive-value-masking-bypass-in-multi"},{"cve":"CVE-2026-59244","cvss":6.5,"epss":0.0039,"slug":"cve-2026-59244-apache-airflow-secrets-exposure-in-rendered-templates-ui","title":"Apache Airflow secrets exposure in Rendered Templates UI","severity":"medium","exploited":false,"published_at":"2026-08-12T16:17:09.197+00:00","url":"https://junglewise.ai/threats/cve-2026-59244-apache-airflow-secrets-exposure-in-rendered-templates-ui"},{"cve":"CVE-2026-59242","cvss":5.4,"epss":0.008,"slug":"cve-2026-59242-apache-airflow-xcom-deserialization-arbitrary-class-instantiation","title":"Apache Airflow XCom deserialization arbitrary class instantiation","severity":"medium","exploited":false,"published_at":"2026-08-12T16:17:09.067+00:00","url":"https://junglewise.ai/threats/cve-2026-59242-apache-airflow-xcom-deserialization-arbitrary-class-instantiation"},{"cve":"CVE-2026-58076","cvss":8.8,"epss":0.0092,"slug":"cve-2026-58076-apache-airflow-unsafe-exception-deserialization-remote-code","title":"Apache Airflow unsafe exception deserialization remote code execution","severity":"high","exploited":false,"published_at":"2026-08-12T16:17:08.317+00:00","url":"https://junglewise.ai/threats/cve-2026-58076-apache-airflow-unsafe-exception-deserialization-remote-code"},{"cve":"CVE-2026-54183","cvss":4.3,"epss":0.0064,"slug":"cve-2026-54183-apache-airflow-secrets-masker-bypass-in-ui-display","title":"Apache Airflow secrets masker bypass in UI display","severity":"medium","exploited":false,"published_at":"2026-08-12T16:17:04.64+00:00","url":"https://junglewise.ai/threats/cve-2026-54183-apache-airflow-secrets-masker-bypass-in-ui-display"},{"cve":"CVE-2025-62402","cvss":3.1,"epss":0.0049,"slug":"cve-2025-62402-apache-airflow-api-v2-dagreports-remote-code-execution","title":"PYSEC-2026-1129 - Apache Airflow `/api/v2/dagReports` executes DAG Python in API","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:09.123674+00:00","url":"https://junglewise.ai/threats/cve-2025-62402-apache-airflow-api-v2-dagreports-remote-code-execution"},{"cve":"CVE-2024-31869","cvss":3.1,"epss":0.0106,"slug":"cve-2024-31869-apache-airflow-sensitive-configuration-disclosure-in-ui","title":"PYSEC-2026-1128 - Apache Airflow: Sensitive configuration for providers displayed when \"non-sensitive-only\" config used","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:39.544374+00:00","url":"https://junglewise.ai/threats/cve-2024-31869-apache-airflow-sensitive-configuration-disclosure-in-ui"},{"cve":"CVE-2026-49487","cvss":6.5,"epss":0.0066,"slug":"cve-2026-49487-apache-airflow-information-disclosure-in-rest-api-task-instance","title":"Apache Airflow information disclosure in REST API task-instance endpoints","severity":"medium","exploited":false,"published_at":"2026-07-07T10:16:41.723+00:00","url":"https://junglewise.ai/threats/cve-2026-49487-apache-airflow-information-disclosure-in-rest-api-task-instance"},{"cve":"CVE-2026-49296","cvss":6.5,"epss":0.006,"slug":"cve-2026-49296-apache-airflow-information-disclosure-in-dag-source-view","title":"Apache Airflow information disclosure in DAG source view","severity":"medium","exploited":false,"published_at":"2026-07-07T10:16:41.603+00:00","url":"https://junglewise.ai/threats/cve-2026-49296-apache-airflow-information-disclosure-in-dag-source-view"},{"cve":"CVE-2026-48892","cvss":6.5,"epss":0.0066,"slug":"cve-2026-48892-apache-airflow-sensitive-information-disclosure-in-config-api","title":"Apache Airflow sensitive information disclosure in Config API","severity":"medium","exploited":false,"published_at":"2026-07-07T10:16:41.48+00:00","url":"https://junglewise.ai/threats/cve-2026-48892-apache-airflow-sensitive-information-disclosure-in-config-api"},{"cve":"CVE-2026-48891","cvss":4.3,"epss":0.0064,"slug":"cve-2026-48891-apache-airflow-information-exposure-in-scheduling-dependency","title":"Apache Airflow information exposure in scheduling dependency graph","severity":"medium","exploited":false,"published_at":"2026-07-07T10:16:41.373+00:00","url":"https://junglewise.ai/threats/cve-2026-48891-apache-airflow-information-exposure-in-scheduling-dependency"},{"cve":"CVE-2026-48828","cvss":6.5,"epss":0.0066,"slug":"cve-2026-48828-apache-airflow-information-exposure-in-bulk-variables-api","title":"Apache Airflow information exposure in Bulk Variables API","severity":"medium","exploited":false,"published_at":"2026-07-07T10:16:41.26+00:00","url":"https://junglewise.ai/threats/cve-2026-48828-apache-airflow-information-exposure-in-bulk-variables-api"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":1,"exploited":0,"vulnerabilities":8},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":12},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":3}],"related":[{"name":"Apache Tomcat","slug":"tomcat","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/tomcat"},{"name":"Apache Camel","slug":"camel","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/camel"},{"name":"Apache Traffic Server","slug":"traffic-server","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/traffic-server"},{"name":"Apache HTTP Server","slug":"http-server","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/http-server"},{"name":"Apache CloudStack","slug":"cloudstack","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/cloudstack"},{"name":"Apache Ofbiz","slug":"ofbiz","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/ofbiz"},{"name":"Apache ActiveMQ","slug":"activemq","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/activemq"},{"name":"Apache Storm","slug":"storm","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/storm"},{"name":"Apache Apisix","slug":"apisix","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/apisix"},{"name":"Apache Thrift","slug":"thrift","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/thrift"},{"name":"Apache ActiveMQ Artemis","slug":"activemq-artemis","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/activemq-artemis"},{"name":"Apache Ranger","slug":"ranger","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/ranger"}],"technology":{"hub":true,"name":"Apache Airflow","slug":"airflow","vendor":{"name":"Apache","slug":"apache","url":"https://junglewise.ai/threats/vendors/apache"},"aliases":[],"category":"workflow-orchestration","homepage":"https://airflow.apache.org","description":"Open-source workflow orchestration platform for authoring, scheduling, and monitoring data pipelines.","url":"https://junglewise.ai/threats/technologies/airflow"},"most_severe":[{"cve":"CVE-2020-13927","cvss":3.1,"epss":0.9978,"slug":"cve-2020-13927-apache-airflow-s-experimental-api-authentication-bypass","title":"PYSEC-2020-18 - The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security ri","severity":"critical","exploited":true,"published_at":"2020-11-10T16:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-13927-apache-airflow-s-experimental-api-authentication-bypass"},{"cve":"CVE-2020-11978","cvss":3.1,"epss":0.9919,"slug":"cve-2020-11978-apache-airflow-command-injection","title":"PYSEC-2020-14 - An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the","severity":"critical","exploited":true,"published_at":"2020-07-17T00:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-11978-apache-airflow-command-injection"},{"cve":"CVE-2026-33264","cvss":9.8,"epss":0.0165,"slug":"cve-2026-33264-apache-airflow-rce-via-deserialization-in-baseserialization","title":"Apache Airflow RCE via Deserialization in BaseSerialization","severity":"critical","exploited":false,"published_at":"2026-07-07T10:16:40.443+00:00","url":"https://junglewise.ai/threats/cve-2026-33264-apache-airflow-rce-via-deserialization-in-baseserialization"},{"cve":"CVE-2026-76186","cvss":9.1,"epss":0.0081,"slug":"cve-2026-76186-apache-airflow-keycloak-provider-session-token-binding-bypass","title":"Apache Airflow Keycloak provider session token binding bypass","severity":"critical","exploited":false,"published_at":"2026-09-16T10:16:52.793+00:00","url":"https://junglewise.ai/threats/cve-2026-76186-apache-airflow-keycloak-provider-session-token-binding-bypass"},{"cve":"CVE-2025-57735","cvss":9.1,"epss":0.0067,"slug":"cve-2025-57735-apache-airflow-insufficient-session-expiration-in-jwt-logout","title":"Apache Airflow insufficient session expiration in JWT logout","severity":"critical","exploited":false,"published_at":"2026-04-09T12:31:11+00:00","url":"https://junglewise.ai/threats/cve-2025-57735-apache-airflow-insufficient-session-expiration-in-jwt-logout"},{"cve":"CVE-2026-42252","cvss":9.1,"epss":0.0059,"slug":"cve-2026-42252-apache-airflow-command-injection-via-unsafe-documentation-example","title":"Apache Airflow command injection via unsafe documentation example","severity":"critical","exploited":false,"published_at":"2026-06-01T09:16:18.56+00:00","url":"https://junglewise.ai/threats/cve-2026-42252-apache-airflow-command-injection-via-unsafe-documentation-example"},{"cve":"CVE-2026-86473","cvss":9.1,"epss":0.0052,"slug":"cve-2026-86473-apache-airflow-the-core-api-logout-endpoint-revokes-only-a","title":"Apache Airflow Core API logout incomplete token revocation","severity":"critical","exploited":false,"published_at":"2026-09-21T15:17:32.997+00:00","url":"https://junglewise.ai/threats/cve-2026-86473-apache-airflow-the-core-api-logout-endpoint-revokes-only-a"},{"cve":"CVE-2024-45498","cvss":8.8,"epss":0.0124,"slug":"cve-2024-45498-apache-airflow-command-execution-in-example-dags","title":"Apache Airflow command execution in example DAGs","severity":"high","exploited":false,"published_at":"2024-09-07T09:30:31+00:00","url":"https://junglewise.ai/threats/cve-2024-45498-apache-airflow-command-execution-in-example-dags"},{"cve":"CVE-2026-67587","cvss":8.8,"epss":0.0117,"slug":"cve-2026-67587-apache-airflow-arbitrary-module-import-via-deserialized-callback","title":"Apache Airflow arbitrary module import via deserialized callback","severity":"high","exploited":false,"published_at":"2026-08-12T16:17:15.09+00:00","url":"https://junglewise.ai/threats/cve-2026-67587-apache-airflow-arbitrary-module-import-via-deserialized-callback"},{"cve":"CVE-2026-33858","cvss":8.8,"epss":0.0106,"slug":"cve-2026-33858-apache-airflow-insecure-deserialization-in-xcom-api","title":"Apache Airflow insecure deserialization in XCom API","severity":"high","exploited":false,"published_at":"2026-04-13T15:17:33.343+00:00","url":"https://junglewise.ai/threats/cve-2026-33858-apache-airflow-insecure-deserialization-in-xcom-api"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}