apache-airflow-providers-amazon
Provider package apache-airflow-providers-amazon for Apache Airflow
Activity
- Latest release
- 3d ago
- Total releases
- 244
- Cadence
- ~4 days
- Last 12 months
- 53
Details
- License
- Apache-2.0
- First release
- Nov 09, 2020
| Version | Released | |
|---|---|---|
9.36.0rc1
pre
|
9.36.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.35.1
patch
|
9.35.1
patch
Dependencies (36)
+ 28 more |
|
9.35.1rc1
pre
|
9.35.1rc1
pre
Dependencies (36)
+ 28 more |
|
9.35.0
minor
|
9.35.0
minor
Dependencies (36)
+ 28 more |
|
9.35.0rc1
pre
|
9.35.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.34.0
minor
|
9.34.0
minor
Dependencies (36)
+ 28 more |
|
9.34.0rc2
pre
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.34.0rc2
pre
Dependencies (36)
+ 28 more |
|
9.34.0rc1
pre
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.34.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.33.0
minor
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.33.0
minor
Dependencies (36)
+ 28 more |
|
9.33.0rc1
pre
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.33.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.32.0
minor
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.32.0
minor
Dependencies (36)
+ 28 more |
|
9.32.0rc1
pre
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.32.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.31.0
minor
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.31.0
minor
Dependencies (36)
+ 28 more |
|
9.31.0rc1
pre
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.31.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.30.0
minor
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.30.0
minor
Dependencies (36)
+ 28 more |
|
9.30.0rc2
pre
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.30.0rc2
pre
Dependencies (36)
+ 28 more |
|
9.30.0rc1
pre
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.30.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.29.0
minor
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.29.0
minor
Dependencies (36)
+ 28 more |
|
9.29.0rc1
pre
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.29.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.28.0
minor
1 CVE
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev |
9.28.0
minor
Dependencies (36)
+ 28 more |
|
9.28.0rc1
pre
2 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.28.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.27.0
minor
2 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.27.0
minor
Dependencies (36)
+ 28 more |
|
9.27.0rc1
pre
2 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.27.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.26.0
minor
2 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.26.0
minor
Dependencies (36)
+ 28 more |
|
9.26.0rc1
pre
2 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.26.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.25.0
minor
2 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.25.0
minor
Dependencies (36)
+ 28 more |
|
9.25.0rc2
pre
2 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.25.0rc2
pre
Dependencies (36)
+ 28 more |
|
9.25.0rc1
pre
2 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.25.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.24.0
minor
2 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.24.0
minor
Dependencies (36)
+ 28 more |
|
9.24.0rc1
pre
2 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.24.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.23.0
minor
2 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.23.0
minor
Dependencies (38)
+ 30 more |
|
9.23.0rc1
pre
2 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.23.0rc1
pre
Dependencies (38)
+ 30 more |
|
9.22.0
minor
2 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.22.0
minor
Dependencies (38)
+ 30 more |
|
9.22.0rc3
pre
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.22.0rc3
pre
Dependencies (38)
+ 30 more |
|
9.22.0rc2
pre
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.22.0rc2
pre
Dependencies (38)
+ 30 more |
|
9.22.0rc1
pre
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.22.0rc1
pre
Dependencies (38)
+ 30 more |
|
9.21.0
minor
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.21.0
minor
Dependencies (38)
+ 30 more |
|
9.21.0rc1
pre
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.21.0rc1
pre
Dependencies (38)
+ 30 more |
|
9.20.0
minor
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.20.0
minor
Dependencies (38)
+ 30 more |
|
9.20.0rc1
pre
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.20.0rc1
pre
Dependencies (38)
+ 30 more |
|
9.19.0
minor
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.19.0
minor
Dependencies (37)
+ 29 more |
|
9.19.0rc1
pre
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.19.0rc1
pre
Dependencies (37)
+ 29 more |
|
9.18.1
patch
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.18.1
patch
Dependencies (37)
+ 29 more |
|
9.18.1rc1
pre
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.18.1rc1
pre
Dependencies (37)
+ 29 more |
|
9.18.0
minor
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.18.0
minor
Dependencies (36)
+ 28 more |
|
9.18.0rc2
pre
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.18.0rc2
pre
Dependencies (36)
+ 28 more |
|
9.18.0rc1
pre
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.18.0rc1
pre
Dependencies (36)
+ 28 more |
|
9.17.0
minor
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.17.0
minor
Dependencies (34)
+ 26 more |
|
9.17.0rc1
pre
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.17.0rc1
pre
Dependencies (34)
+ 26 more |
|
9.16.0
minor
3 CVEs
CVE-2026-68872
PYSEC-2026-3713
Aug 10, 2026
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 226 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0
9.28.0rc1
9.29.0
9.29.0rc1
9.3.0
9.30.0
9.30.0rc1
9.30.0rc2
9.31.0
9.31.0rc1
9.32.0
9.32.0rc1
9.33.0
9.33.0rc1
9.34.0rc1
9.34.0rc2
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.34.0
References Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-25604
PYSEC-2026-2363
GHSA-rv5f-ccpm-xjj4
Jul 13, 2026
Apache Airflow AWS Auth Manager has Host Header Injection Leading to SAML Authentication Bypass
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 199 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.22.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42526
GHSA-g9qc-qf28-hhqx
PYSEC-2026-595
May 19, 2026
Apache Airflow Amazon provider: Prevent unauthorized access to team-scoped secrets in AWS Secrets Manager and SSM Parameter Store backends
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
In the AWS Secrets Manager and SSM Parameter Store secrets backends of Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.1.0
1.1.0rc1
1.2.0
1.2.0rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
+ 212 more Show less
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.2.0
2.2.0rc1
2.3.0
2.3.0rc1
2.3.0rc2
2.4.0
2.4.0rc1
2.4.0rc2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0rc1
3.1.1
3.1.1rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
4.0.0
4.0.0rc1
4.0.0rc2
4.1.0
4.1.0rc1
5.0.0
5.0.0rc1
5.0.0rc2
5.0.0rc3
5.1.0
5.1.0rc1
6.0.0
6.0.0rc1
6.1.0
6.1.0rc1
6.2.0
6.2.0rc2
6.2.0rc3
7.0.0
7.0.0rc1
7.0.0rc2
7.1.0
7.1.0rc1
7.2.0
7.2.0rc1
7.2.1
7.2.1rc1
7.3.0
7.3.0rc1
7.4.0
7.4.0rc1
7.4.1
7.4.1rc1
8.0.0
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.1.0
8.1.0rc1
8.1.0rc2
8.10.0
8.10.0rc1
8.11.0
8.11.0rc1
8.12.0
8.12.0rc1
8.13.0
8.13.0rc1
8.14.0
8.14.0rc1
8.15.0
8.15.0rc1
8.16.0
8.16.0rc1
8.17.0
8.17.0rc1
8.17.0rc2
8.18.0
8.18.0rc1
8.18.0rc2
8.19.0
8.19.0rc1
8.2.0
8.2.0rc1
8.20.0
8.20.0rc1
8.21.0
8.21.0rc1
8.22.0
8.22.0rc1
8.23.0
8.23.0rc1
8.24.0
8.24.0rc1
8.24.0rc2
8.25.0
8.25.0rc1
8.26.0
8.26.0rc1
8.26.0rc2
8.27.0
8.27.0rc1
8.27.0rc2
8.28.0
8.28.0rc1
8.29.0
8.29.0rc1
8.3.0
8.3.0rc1
8.3.0rc2
8.3.0rc3
8.3.0rc4
8.3.1
8.3.1rc1
8.4.0
8.4.0rc1
8.5.0
8.5.0rc1
8.5.1
8.5.1rc1
8.6.0
8.6.0rc1
8.7.0
8.7.0rc1
8.7.1
8.7.1rc1
8.8.0
8.8.0rc1
8.9.0
8.9.0rc1
9.0.0
9.0.0rc1
9.1.0
9.1.0rc1
9.1.0rc2
9.1.0rc3
9.1.0rc4
9.10.0
9.10.0rc1
9.11.0
9.11.0rc1
9.12.0
9.12.0rc1
9.13.0
9.13.0rc1
9.14.0
9.14.0rc1
9.15.0
9.15.0rc1
9.16.0
9.16.0rc1
9.17.0
9.17.0rc1
9.18.0
9.18.0rc1
9.18.0rc2
9.18.1
9.18.1rc1
9.19.0
9.19.0rc1
9.2.0
9.2.0rc1
9.2.0rc2
9.20.0
9.20.0rc1
9.21.0
9.21.0rc1
9.22.0
9.22.0rc1
9.22.0rc2
9.22.0rc3
9.23.0
9.23.0rc1
9.24.0
9.24.0rc1
9.25.0
9.25.0rc1
9.25.0rc2
9.26.0
9.26.0rc1
9.27.0
9.27.0rc1
9.28.0rc1
9.3.0
9.4.0
9.4.0rc1
9.5.0
9.5.0rc1
9.5.0rc2
9.5.0rc3
9.6.0
9.6.0rc1
9.6.1
9.6.1rc1
9.7.0
9.7.0rc1
9.7.0rc2
9.8.0
9.8.0rc1
9.9.0
9.9.0rc1
9.9.1rc1
Fixed in
9.28.0
References Updated Jul 01, 2026 · Source: OSV.dev |
9.16.0
minor
Dependencies (34)
+ 26 more |