apache-airflow-core
Core packages for Apache Airflow, schedule and API server
Activity
- Latest release
- 22h ago
- Total releases
- 79
- Cadence
- ~4 days
- Last 12 months
- 43
Details
- License
- Apache-2.0
- First release
- Apr 03, 2025
| Version | Released | |
|---|---|---|
3.3.2rc1
pre
|
3.3.2rc1
pre
Dependencies (77)
+ 69 more |
|
3.3.1
patch
|
3.3.1
patch
Dependencies (77)
+ 69 more |
|
3.3.1rc2
pre
|
3.3.1rc2
pre
Dependencies (77)
+ 69 more |
|
3.3.1rc1
pre
|
3.3.1rc1
pre
Dependencies (77)
+ 69 more |
|
3.3.0
minor
|
3.3.0
minor
Dependencies (77)
+ 69 more |
|
3.3.0rc2
pre
|
3.3.0rc2
pre
Dependencies (77)
+ 69 more |
|
3.3.0rc1
pre
|
3.3.0rc1
pre
Dependencies (77)
+ 69 more |
|
3.3.0b2
pre
|
3.3.0b2
pre
Dependencies (77)
+ 69 more |
|
3.3.0b1
pre
|
3.3.0b1
pre
Dependencies (78)
+ 70 more |
|
3.2.2
patch
|
3.2.2
patch
Dependencies (76)
+ 68 more |
|
3.2.2rc3
pre
1 CVE
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev |
3.2.2rc3
pre
Dependencies (76)
+ 68 more |
|
3.2.2rc2
pre
1 CVE
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev |
3.2.2rc2
pre
Dependencies (76)
+ 68 more |
|
3.2.2rc1
pre
1 CVE
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev |
3.2.2rc1
pre
Dependencies (76)
+ 68 more |
|
3.2.1
patch
1 CVE
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev |
3.2.1
patch
Dependencies (75)
+ 67 more |
|
3.2.1rc3
pre
1 CVE
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev |
3.2.1rc3
pre
Dependencies (75)
+ 67 more |
|
3.2.1rc2
pre
1 CVE
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev |
3.2.1rc2
pre
Dependencies (75)
+ 67 more |
|
3.2.1rc1
pre
1 CVE
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev |
3.2.1rc1
pre
Dependencies (75)
+ 67 more |
|
3.2.0
minor
1 CVE
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev |
3.2.0
minor
Dependencies (75)
+ 67 more |
|
3.2.0rc2
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.2.0rc2
pre
Dependencies (75)
+ 67 more |
|
3.2.0rc1
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.2.0rc1
pre
Dependencies (75)
+ 67 more |
|
3.2.0b2
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.2.0b2
pre
Dependencies (75)
+ 67 more |
|
3.1.8
patch
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.8
patch
Dependencies (76)
+ 68 more |
|
3.1.8rc2
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.8rc2
pre
Dependencies (76)
+ 68 more |
|
3.1.8rc1
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.8rc1
pre
Dependencies (76)
+ 68 more |
|
3.2.0b1
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.2.0b1
pre
Dependencies (75)
+ 67 more |
|
3.1.7
patch
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.7
patch
Dependencies (76)
+ 68 more |
|
3.1.7rc2
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.7rc2
pre
Dependencies (76)
+ 68 more |
|
3.1.7rc1
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.7rc1
pre
Dependencies (76)
+ 68 more |
|
3.1.6
patch
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.6
patch
Dependencies (76)
+ 68 more |
|
3.1.6rc1
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.6rc1
pre
Dependencies (76)
+ 68 more |
|
3.1.5
patch
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.5
patch
Dependencies (76)
+ 68 more |
|
3.1.5rc1
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.5rc1
pre
Dependencies (76)
+ 68 more |
|
3.1.4
patch
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.4
patch
Dependencies (76)
+ 68 more |
|
3.1.4rc2
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.4rc2
pre
Dependencies (76)
+ 68 more |
|
3.1.4rc1
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.4rc1
pre
Dependencies (76)
+ 68 more |
|
3.1.3
patch
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.3
patch
Dependencies (76)
+ 68 more |
|
3.1.3rc1
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.3rc1
pre
Dependencies (76)
+ 68 more |
|
3.1.2
patch
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.2
patch
Dependencies (75)
+ 67 more |
|
3.1.2rc2
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.2rc2
pre
Dependencies (75)
+ 67 more |
|
3.1.2rc1
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.2rc1
pre
Dependencies (75)
+ 67 more |
|
3.1.1
patch
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.1
patch
Dependencies (75)
+ 67 more |
|
3.1.1rc2
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.1rc2
pre
Dependencies (75)
+ 67 more |
|
3.1.1rc1
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.1rc1
pre
Dependencies (75)
+ 67 more |
|
3.1.0
minor
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.0
minor
Dependencies (74)
+ 66 more |
|
3.1.0rc2
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.0rc2
pre
Dependencies (74)
+ 66 more |
|
3.1.0rc1
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.0rc1
pre
Dependencies (74)
+ 66 more |
|
3.1.0b2
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.0b2
pre
Dependencies (73)
+ 65 more |
|
3.1.0b1
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.0b1
pre
Dependencies (73)
+ 65 more |
|
3.0.6
patch
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.0.6
patch
Dependencies (71)
+ 63 more |
|
3.0.6rc2
pre
5 CVEs
CVE-2026-49298
PYSEC-2026-2358
BIT-airflow-2026-49298
GHSA-5j6p-jrrm-6x94
Jul 13, 2026
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 57 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
3.2.1
3.2.1rc1
3.2.1rc2
3.2.1rc3
3.2.2rc1
3.2.2rc2
3.2.2rc3
Fixed in
3.2.2
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-25917
PYSEC-2026-2359
BIT-airflow-2026-25917
GHSA-6ffj-2wg2-w45j
PYSEC-2026-13
Jul 13, 2026
Apache Airflow allows code execution through crafted XCom payloads
7.2
/ 10
High
Network
Low
High
None
Unchanged
High
High
High
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-30912
PYSEC-2026-2361
BIT-airflow-2026-30912
GHSA-w7cf-2pmc-5m4c
PYSEC-2026-18
Jul 13, 2026
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. Affected versions
3.0.0
3.0.0rc1
3.0.0rc1.post1
3.0.0rc1.post2
3.0.0rc1.post3
3.0.0rc1.post4
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.1
3.0.1rc1
3.0.2
+ 49 more Show less
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32228
PYSEC-2026-2360
BIT-airflow-2026-32228
GHSA-h97w-pm3w-mwmc
Jul 13, 2026
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32690
PYSEC-2026-2362
BIT-airflow-2026-32690
GHSA-w9r4-94fj-xp69
PYSEC-2026-19
Jul 13, 2026
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked. If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0. Affected versions
3.0.0
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.2rc2
3.0.3
3.0.3rc1
3.0.3rc2
3.0.3rc3
3.0.3rc4
3.0.3rc5
+ 41 more Show less
3.0.3rc6
3.0.4
3.0.4rc1
3.0.4rc2
3.0.5
3.0.5rc1
3.0.5rc2
3.0.5rc3
3.0.6
3.0.6rc1
3.0.6rc2
3.1.0
3.1.0b1
3.1.0b2
3.1.0rc1
3.1.0rc2
3.1.1
3.1.1rc1
3.1.1rc2
3.1.2
3.1.2rc1
3.1.2rc2
3.1.3
3.1.3rc1
3.1.4
3.1.4rc1
3.1.4rc2
3.1.5
3.1.5rc1
3.1.6
3.1.6rc1
3.1.7
3.1.7rc1
3.1.7rc2
3.1.8
3.1.8rc1
3.1.8rc2
3.2.0b1
3.2.0b2
3.2.0rc1
3.2.0rc2
Fixed in
3.2.0
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.0.6rc2
pre
Dependencies (71)
+ 63 more |