Known vulnerabilities in Apache Airflow

Software CPE: cpe:2.3:a:apache_foundation:apache_airflow:*:*:*:*:*:*:*:*
Total vulnerabilities: 79
Public exploits: 4
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache Airflow Apache Airflow is affected by 79 known vulnerabilities: 8 high, 22 medium, 49 low Critical High Medium Low

Vulnerabilities (79)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU133390 - Exposure of sensitive information to an unauthorized actor
CVE-2026-49298
CWE-200 Medium
No
No
3.2.2 04.06.2026 SB2026060498
#VU133389 - Insufficient Session Expiration
CVE-2026-48726
CWE-613 Low
No
No
3.2.2 04.06.2026 SB2026060498
#VU133388 - Exposure of sensitive information to an unauthorized actor
CVE-2026-45192
CWE-200 Low
No
No
3.2.2 04.06.2026 SB2026060498
#VU133387 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2026-41017
CWE-614 High
No
No
3.2.2 04.06.2026 SB2026060498
#VU133386 - Improper input validation
CVE-2026-42359
CWE-20 Medium
No
No
3.2.2 04.06.2026 SB2026060498
#VU133385 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-45360
CWE-94 Medium
No
No
3.2.2 04.06.2026 SB2026060498
#VU133384 - Improper Authorization
CVE-2026-45426
CWE-285 Low
No
No
3.2.2 04.06.2026 SB2026060498
#VU133383 - Improper Access Control
CVE-2026-46764
CWE-284 Low
No
No
3.2.2 04.06.2026 SB2026060498
#VU133382 - Exposure of sensitive information to an unauthorized actor
CVE-2026-42358
CWE-200 Low
No
No
3.2.2 04.06.2026 SB2026060498
#VU133381 - Exposure of sensitive information to an unauthorized actor
CVE-2026-42360
CWE-200 Low
No
No
3.2.2 04.06.2026 SB2026060498
#VU133380 - Command injection
CVE-2026-42252
CWE-77 Medium
No
No
3.2.2 04.06.2026 SB2026060498
#VU133379 - Improper Access Control
CVE-2026-41084
CWE-284 Low
No
No
3.2.2 04.06.2026 SB2026060498
#VU133378 - Improper Certificate Validation
CVE-2026-49267
CWE-295 Medium
No
No
3.2.2 04.06.2026 SB2026060498
#VU133377 - Improper Access Control
CVE-2026-41014
CWE-284 Low
No
No
3.2.2 04.06.2026 SB2026060498
#VU133376 - Improper Access Control
CVE-2026-40963
CWE-284 Low
No
No
3.2.2 04.06.2026 SB2026060498
#VU133375 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2026-40961
CWE-601 Low
No
No
3.2.2 04.06.2026 SB2026060498
#VU133374 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-40861
CWE-59 Low
No
No
3.2.2 04.06.2026 SB2026060498
#VU121616 - Exposure of sensitive information to an unauthorized actor
CVE-2025-68438
CWE-200 Medium
No
No
3.1.6 16.01.2026 SB2026011618
#VU121615 - Information Exposure Through Log Files
CVE-2025-68675
CWE-532 Low
No
No
3.1.6 16.01.2026 SB2026011618
#VU120169 - Unprotected Storage of Credentials
CVE-2025-66388
CWE-256 Medium
No
No
3.1.4 17.12.2025 SB2025121728


Showing elements 1 - 20 out of 79