Known vulnerabilities in Apache Airflow

Software CPE: cpe:2.3:a:apache_foundation:apache_airflow:*:*:*:*:*:*:*:*
Total vulnerabilities: 110
Public exploits: 4
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache Airflow Apache Airflow is affected by 110 known vulnerabilities: 8 high, 28 medium, 74 low Critical High Medium Low

Vulnerabilities (110)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU145333 - Improper Access Control
CVE-2026-40690
CWE-284 Low
No
No
3.2.1 25.08.2026 SB20260825108
#VU145332 - Improper Access Control
CVE-2026-38743
CWE-284 Low
No
No
3.2.1 25.08.2026 SB20260825108
#VU145329 - Deserialization of Untrusted Data
CVE-2026-25917
CWE-502 Low
No
No
3.2.0 25.08.2026 SB20260825102
#VU145328 - Improper Access Control
CVE-2026-32228
CWE-284 Low
No
No
3.2.0 25.08.2026 SB20260825102
#VU145327 - Command injection
CVE-2026-30898
CWE-77 Low
No
No
3.2.0 25.08.2026 SB20260825102
#VU145326 - Exposure of sensitive information to an unauthorized actor
CVE-2026-32690
CWE-200 Low
No
No
3.2.0 25.08.2026 SB20260825102
#VU145325 - Information Exposure Through an Error Message
CVE-2026-30912
CWE-209 Medium
No
No
3.2.0 25.08.2026 SB20260825102
#VU145324 - Information Exposure Through Log Files
CVE-2026-31987
CWE-532 Low
No
No
3.2.0 25.08.2026 SB20260825102
#VU145322 - Deserialization of Untrusted Data
CVE-2025-54550
CWE-502 Medium
No
No
3.2.0 25.08.2026 SB20260825102
#VU145317 - Deserialization of Untrusted Data
CVE-2026-33858
CWE-502 Low
No
No
3.2.0 25.08.2026 SB20260825102
#VU145316 - Information Exposure Through Log Files
CVE-2025-66236
CWE-532 Low
No
No
3.2.0 25.08.2026 SB20260825102
#VU145312 - Insufficient Session Expiration
CVE-2025-57735
CWE-613 Low
No
No
3.2.0 25.08.2026 SB20260825102
#VU145311 - Improper Access Control
CVE-2026-34538
CWE-284 Low
No
No
3.2.0 25.08.2026 SB20260825102
#VU144878 - Exposure of sensitive information to an unauthorized actor
CVE-2026-65017
CWE-200 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144877 - Deserialization of Untrusted Data
CVE-2026-67587
CWE-502 Medium
No
No
3.3.1 24.08.2026 SB20260824160
#VU144876 - Deserialization of Untrusted Data
CVE-2026-67260
CWE-502 Medium
No
No
3.3.1 24.08.2026 SB20260824160
#VU144875 - Exposure of sensitive information to an unauthorized actor
CVE-2026-54183
CWE-200 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144874 - Deserialization of Untrusted Data
CVE-2026-59242
CWE-502 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144873 - Exposure of sensitive information to an unauthorized actor
CVE-2026-59244
CWE-200 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144872 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-58076
CWE-94 Medium
No
No
3.3.1 24.08.2026 SB20260824160


Showing elements 1 - 20 out of 110