Technology · PyPI
apache-airflow (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 40 vulnerabilities in apache-airflow (PyPI): 0 in the last 7 days and 6 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-49487, was published on 7 July 2026.
- Last 7 days
- 0
- Last 90 days
- 6
- Critical, all time
- 3
- Exploited in the wild
- 0
About apache-airflow (PyPI)
A platform to programmatically author, schedule, and monitor workflows.
Latest apache-airflow (PyPI) vulnerabilities
- CVE-2026-49487: Apache Airflow information disclosure in REST API task-instance endpointsmediumCVSS 6.5EPSS 0.7%
- CVE-2026-49296: Apache Airflow information disclosure in DAG source viewmediumCVSS 6.5EPSS 0.6%
- CVE-2026-48892: Apache Airflow sensitive information disclosure in Config APImediumCVSS 6.5EPSS 0.7%
- CVE-2026-48891: Apache Airflow information exposure in scheduling dependency graphmediumCVSS 4.3EPSS 0.6%
- CVE-2026-48828: Apache Airflow information exposure in Bulk Variables APImediumCVSS 6.5EPSS 0.7%
- CVE-2026-33264: Apache Airflow RCE via Deserialization in BaseSerializationcriticalCVSS 9.8EPSS 1.7%
- CVE-2026-49267: Apache Airflow SMTP certificate validation bypass in EmailOperatormediumCVSS 5.9EPSS 0.3%
- CVE-2026-48726: Apache Airflow insufficient session expiration in FAB and Keycloak logoutmediumCVSS 6.5EPSS 0.4%
- CVE-2026-46764: Apache Airflow authorization bypass in Event Log detail endpointmediumCVSS 4.3EPSS 0.4%
- CVE-2026-45426: Apache Airflow authorization bypass in Log server via Python lstriplowCVSS 3.1EPSS 0.3%
- CVE-2026-45360: Apache Airflow arbitrary code execution in deadline-reference decoderhighCVSS 7.3EPSS 0.9%
- CVE-2026-42360: Apache Airflow sensitive information disclosure in rendered templatesmediumCVSS 6.5EPSS 0.5%
- CVE-2026-42359: Apache Airflow RCE via XCom PATCH endpoint bypasshighCVSS 8.8EPSS 0.5%
- CVE-2026-42358: Apache Airflow sensitive information disclosure in Variable maskermediumCVSS 6.5EPSS 0.5%
- CVE-2026-42252: Apache Airflow command injection via unsafe documentation examplecriticalCVSS 9.1EPSS 0.6%
- CVE-2026-41084: Apache Airflow auth bypass in bulk Task Instances APIhighCVSS 7.5EPSS 0.8%
- CVE-2026-41017: Apache Airflow missing Secure flag in JWTRefreshMiddlewaremediumCVSS 5.9EPSS 0.4%
- CVE-2026-41014: Apache Airflow missing authorization in partitioned_dag_runs endpointsmediumCVSS 4.3EPSS 0.4%
- CVE-2026-40963: Apache Airflow improper authorization in structure_data endpointlowCVSS 3.1EPSS 0.5%
- CVE-2026-40961: Apache Airflow open redirect in login redirect routehighCVSS 7.2EPSS 0.8%
- CVE-2026-40861: Apache Airflow arbitrary file read/write in FileTaskHandlermediumCVSS 6.5EPSS 0.8%
- CVE-2026-45192: Apache Airflow information exposure in Connection API extra fieldmediumCVSS 6.5EPSS 0.7%
- CVE-2026-32690: Apache Airflow information exposure in JSON dictionary variableslowCVSS 3.7EPSS 0.1%
- CVE-2026-31987: Apache Airflow: JWT token appearing in logshighCVSS 7.5EPSS 0.8%
- CVE-2025-54550: Apache Airflow RCE in example_xcom DAG documentationhighCVSS 8.1EPSS 0.6%
Most severe apache-airflow (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-33264: Apache Airflow RCE via Deserialization in BaseSerializationcriticalCVSS 9.8EPSS 1.7%
- CVE-2025-57735: Apache Airflow insufficient session expiration in JWT logoutcriticalCVSS 9.1EPSS 0.7%
- CVE-2026-42252: Apache Airflow command injection via unsafe documentation examplecriticalCVSS 9.1EPSS 0.6%
- CVE-2024-45498: Apache Airflow command execution in example DAGshighCVSS 8.8EPSS 1.2%
- CVE-2026-33858: Apache Airflow insecure deserialization in XCom APIhighCVSS 8.8EPSS 1.1%
- CVE-2026-42359: Apache Airflow RCE via XCom PATCH endpoint bypasshighCVSS 8.8EPSS 0.5%
- CVE-2026-30911: Apache Airflow missing authorization in Execution API HITL endpointshighCVSS 8.1EPSS 0.7%
- CVE-2025-54550: Apache Airflow RCE in example_xcom DAG documentationhighCVSS 8.1EPSS 0.6%
- CVE-2026-31987: Apache Airflow: JWT token appearing in logshighCVSS 7.5EPSS 0.8%
- CVE-2026-41084: Apache Airflow auth bypass in bulk Task Instances APIhighCVSS 7.5EPSS 0.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 6 | 1 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/apache-airflow.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "apache-airflow (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/apache-airflow, 26 September 2026.