apache-airflow-providers-mysql
Provider package apache-airflow-providers-mysql for Apache Airflow
Activity
- Latest release
- 3w ago
- Total releases
- 140
- Cadence
- ~5 days
- Last 12 months
- 24
Details
- License
- Apache-2.0
- First release
- Nov 09, 2020
| Version | Released | |
|---|---|---|
6.6.2
patch
|
6.6.2
patch
Dependencies (12)
+ 4 more |
|
6.6.2rc1
pre
|
6.6.2rc1
pre
Dependencies (12)
+ 4 more |
|
6.6.1
patch
|
6.6.1
patch
Dependencies (12)
+ 4 more |
|
6.6.1rc1
pre
|
6.6.1rc1
pre
Dependencies (12)
+ 4 more |
|
6.6.0
minor
|
6.6.0
minor
Dependencies (11)
+ 3 more |
|
6.6.0rc1
pre
|
6.6.0rc1
pre
Dependencies (11)
+ 3 more |
|
6.5.3
patch
|
6.5.3
patch
Dependencies (11)
+ 3 more |
|
6.5.3rc1
pre
|
6.5.3rc1
pre
Dependencies (11)
+ 3 more |
|
6.5.2
patch
|
6.5.2
patch
Dependencies (11)
+ 3 more |
|
6.5.2rc1
pre
|
6.5.2rc1
pre
Dependencies (11)
+ 3 more |
|
6.5.1
patch
|
6.5.1
patch
Dependencies (11)
+ 3 more |
|
6.5.1rc1
pre
|
6.5.1rc1
pre
Dependencies (11)
+ 3 more |
|
6.5.0
minor
|
6.5.0
minor
Dependencies (11)
+ 3 more |
|
6.5.0rc1
pre
|
6.5.0rc1
pre
Dependencies (11)
+ 3 more |
|
6.4.3
patch
|
6.4.3
patch
Dependencies (11)
+ 3 more |
|
6.4.3rc1
pre
|
6.4.3rc1
pre
Dependencies (11)
+ 3 more |
|
6.4.2
patch
|
6.4.2
patch
Dependencies (11)
+ 3 more |
|
6.4.2rc1
pre
|
6.4.2rc1
pre
Dependencies (11)
+ 3 more |
|
6.4.1
patch
|
6.4.1
patch
Dependencies (11)
+ 3 more |
|
6.4.1rc1
pre
|
6.4.1rc1
pre
Dependencies (11)
+ 3 more |
|
6.4.0
minor
|
6.4.0
minor
Dependencies (11)
+ 3 more |
|
6.4.0rc1
pre
|
6.4.0rc1
pre
Dependencies (11)
+ 3 more |
|
6.3.5
patch
|
6.3.5
patch
Dependencies (11)
+ 3 more |
|
6.3.5rc1
pre
|
6.3.5rc1
pre
Dependencies (11)
+ 3 more |
|
6.3.4
patch
|
6.3.4
patch
Dependencies (10)
+ 2 more |
|
6.3.4rc1
pre
|
6.3.4rc1
pre
Dependencies (10)
+ 2 more |
|
6.3.3
patch
|
6.3.3
patch
Dependencies (10)
+ 2 more |
|
6.3.3rc1
pre
|
6.3.3rc1
pre
Dependencies (10)
+ 2 more |
|
6.3.2
patch
|
6.3.2
patch
Dependencies (10)
+ 2 more |
|
6.3.2rc1
pre
|
6.3.2rc1
pre
Dependencies (10)
+ 2 more |
|
6.3.1
patch
|
6.3.1
patch
Dependencies (10)
+ 2 more |
|
6.3.1rc1
pre
|
6.3.1rc1
pre
Dependencies (10)
+ 2 more |
|
6.3.0
minor
|
6.3.0
minor
Dependencies (10)
+ 2 more |
|
6.3.0rc1
pre
|
6.3.0rc1
pre
Dependencies (10)
+ 2 more |
|
6.2.2
patch
|
6.2.2
patch
Dependencies (10)
+ 2 more |
|
6.2.2rc1
pre
|
6.2.2rc1
pre
Dependencies (10)
+ 2 more |
|
6.2.1
patch
|
6.2.1
patch
Dependencies (10)
+ 2 more |
|
6.2.1rc1
pre
|
6.2.1rc1
pre
Dependencies (10)
+ 2 more |
|
6.2.0
minor
|
6.2.0
minor
Dependencies (10)
+ 2 more |
|
6.2.0rc1
pre
1 CVE
CVE-2025-27018
PYSEC-2026-1151
GHSA-hhm6-jjf4-6pm3
Jul 07, 2026
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Medium
Network
Low
Low
None
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.1
1.0.1rc1
1.0.2
1.0.2rc1
1.1.0
1.1.0rc1
2.0.0
2.0.0rc1
+ 89 more Show less
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.1.1
2.1.1rc1
2.2.0
2.2.0rc1
2.2.0rc2
2.2.1
2.2.1rc1
2.2.2
2.2.2rc1
2.2.3
2.2.3rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.0rc1
3.2.0
3.2.0rc1
3.2.0rc2
3.2.0rc3
3.2.1
3.2.1rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc2
3.4.0rc3
4.0.0
4.0.0rc1
4.0.1
4.0.1rc1
4.0.2
4.0.2rc1
5.0.0
5.0.0rc1
5.1.0
5.1.0rc1
5.1.0rc2
5.1.1
5.1.1rc1
5.2.0
5.2.0rc1
5.2.1
5.2.1rc1
5.3.0
5.3.0rc1
5.3.1
5.3.1rc1
5.4.0
5.4.0rc1
5.5.0
5.5.0rc1
5.5.1
5.5.1rc1
5.5.2
5.5.2rc1
5.5.2rc2
5.5.3
5.5.3rc1
5.5.4
5.5.4rc1
5.6.0
5.6.0rc1
5.6.1
5.6.1rc1
5.6.2
5.6.2rc1
5.6.3
5.6.3rc1
5.7.0
5.7.0rc1
5.7.1
5.7.1rc1
5.7.2
5.7.2rc1
5.7.3
5.7.3rc1
5.7.4
5.7.4rc1
6.0.0
6.0.0rc1
6.0.0rc2
6.1.0
6.1.0rc1
6.2.0rc1
Fixed in
6.2.0
References Updated Jul 07, 2026 · Source: OSV.dev |
6.2.0rc1
pre
Dependencies (10)
+ 2 more |
|
6.1.0
minor
1 CVE
CVE-2025-27018
PYSEC-2026-1151
GHSA-hhm6-jjf4-6pm3
Jul 07, 2026
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Medium
Network
Low
Low
None
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.1
1.0.1rc1
1.0.2
1.0.2rc1
1.1.0
1.1.0rc1
2.0.0
2.0.0rc1
+ 89 more Show less
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.1.1
2.1.1rc1
2.2.0
2.2.0rc1
2.2.0rc2
2.2.1
2.2.1rc1
2.2.2
2.2.2rc1
2.2.3
2.2.3rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.0rc1
3.2.0
3.2.0rc1
3.2.0rc2
3.2.0rc3
3.2.1
3.2.1rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc2
3.4.0rc3
4.0.0
4.0.0rc1
4.0.1
4.0.1rc1
4.0.2
4.0.2rc1
5.0.0
5.0.0rc1
5.1.0
5.1.0rc1
5.1.0rc2
5.1.1
5.1.1rc1
5.2.0
5.2.0rc1
5.2.1
5.2.1rc1
5.3.0
5.3.0rc1
5.3.1
5.3.1rc1
5.4.0
5.4.0rc1
5.5.0
5.5.0rc1
5.5.1
5.5.1rc1
5.5.2
5.5.2rc1
5.5.2rc2
5.5.3
5.5.3rc1
5.5.4
5.5.4rc1
5.6.0
5.6.0rc1
5.6.1
5.6.1rc1
5.6.2
5.6.2rc1
5.6.3
5.6.3rc1
5.7.0
5.7.0rc1
5.7.1
5.7.1rc1
5.7.2
5.7.2rc1
5.7.3
5.7.3rc1
5.7.4
5.7.4rc1
6.0.0
6.0.0rc1
6.0.0rc2
6.1.0
6.1.0rc1
6.2.0rc1
Fixed in
6.2.0
References Updated Jul 07, 2026 · Source: OSV.dev |
6.1.0
minor
Dependencies (10)
+ 2 more |
|
6.1.0rc1
pre
1 CVE
CVE-2025-27018
PYSEC-2026-1151
GHSA-hhm6-jjf4-6pm3
Jul 07, 2026
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Medium
Network
Low
Low
None
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.1
1.0.1rc1
1.0.2
1.0.2rc1
1.1.0
1.1.0rc1
2.0.0
2.0.0rc1
+ 89 more Show less
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.1.1
2.1.1rc1
2.2.0
2.2.0rc1
2.2.0rc2
2.2.1
2.2.1rc1
2.2.2
2.2.2rc1
2.2.3
2.2.3rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.0rc1
3.2.0
3.2.0rc1
3.2.0rc2
3.2.0rc3
3.2.1
3.2.1rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc2
3.4.0rc3
4.0.0
4.0.0rc1
4.0.1
4.0.1rc1
4.0.2
4.0.2rc1
5.0.0
5.0.0rc1
5.1.0
5.1.0rc1
5.1.0rc2
5.1.1
5.1.1rc1
5.2.0
5.2.0rc1
5.2.1
5.2.1rc1
5.3.0
5.3.0rc1
5.3.1
5.3.1rc1
5.4.0
5.4.0rc1
5.5.0
5.5.0rc1
5.5.1
5.5.1rc1
5.5.2
5.5.2rc1
5.5.2rc2
5.5.3
5.5.3rc1
5.5.4
5.5.4rc1
5.6.0
5.6.0rc1
5.6.1
5.6.1rc1
5.6.2
5.6.2rc1
5.6.3
5.6.3rc1
5.7.0
5.7.0rc1
5.7.1
5.7.1rc1
5.7.2
5.7.2rc1
5.7.3
5.7.3rc1
5.7.4
5.7.4rc1
6.0.0
6.0.0rc1
6.0.0rc2
6.1.0
6.1.0rc1
6.2.0rc1
Fixed in
6.2.0
References Updated Jul 07, 2026 · Source: OSV.dev |
6.1.0rc1
pre
Dependencies (10)
+ 2 more |
|
6.0.0
major
1 CVE
CVE-2025-27018
PYSEC-2026-1151
GHSA-hhm6-jjf4-6pm3
Jul 07, 2026
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Medium
Network
Low
Low
None
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.1
1.0.1rc1
1.0.2
1.0.2rc1
1.1.0
1.1.0rc1
2.0.0
2.0.0rc1
+ 89 more Show less
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.1.1
2.1.1rc1
2.2.0
2.2.0rc1
2.2.0rc2
2.2.1
2.2.1rc1
2.2.2
2.2.2rc1
2.2.3
2.2.3rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.0rc1
3.2.0
3.2.0rc1
3.2.0rc2
3.2.0rc3
3.2.1
3.2.1rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc2
3.4.0rc3
4.0.0
4.0.0rc1
4.0.1
4.0.1rc1
4.0.2
4.0.2rc1
5.0.0
5.0.0rc1
5.1.0
5.1.0rc1
5.1.0rc2
5.1.1
5.1.1rc1
5.2.0
5.2.0rc1
5.2.1
5.2.1rc1
5.3.0
5.3.0rc1
5.3.1
5.3.1rc1
5.4.0
5.4.0rc1
5.5.0
5.5.0rc1
5.5.1
5.5.1rc1
5.5.2
5.5.2rc1
5.5.2rc2
5.5.3
5.5.3rc1
5.5.4
5.5.4rc1
5.6.0
5.6.0rc1
5.6.1
5.6.1rc1
5.6.2
5.6.2rc1
5.6.3
5.6.3rc1
5.7.0
5.7.0rc1
5.7.1
5.7.1rc1
5.7.2
5.7.2rc1
5.7.3
5.7.3rc1
5.7.4
5.7.4rc1
6.0.0
6.0.0rc1
6.0.0rc2
6.1.0
6.1.0rc1
6.2.0rc1
Fixed in
6.2.0
References Updated Jul 07, 2026 · Source: OSV.dev |
6.0.0
major
Dependencies (10)
+ 2 more |
|
6.0.0rc2
pre
1 CVE
CVE-2025-27018
PYSEC-2026-1151
GHSA-hhm6-jjf4-6pm3
Jul 07, 2026
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Medium
Network
Low
Low
None
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.1
1.0.1rc1
1.0.2
1.0.2rc1
1.1.0
1.1.0rc1
2.0.0
2.0.0rc1
+ 89 more Show less
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.1.1
2.1.1rc1
2.2.0
2.2.0rc1
2.2.0rc2
2.2.1
2.2.1rc1
2.2.2
2.2.2rc1
2.2.3
2.2.3rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.0rc1
3.2.0
3.2.0rc1
3.2.0rc2
3.2.0rc3
3.2.1
3.2.1rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc2
3.4.0rc3
4.0.0
4.0.0rc1
4.0.1
4.0.1rc1
4.0.2
4.0.2rc1
5.0.0
5.0.0rc1
5.1.0
5.1.0rc1
5.1.0rc2
5.1.1
5.1.1rc1
5.2.0
5.2.0rc1
5.2.1
5.2.1rc1
5.3.0
5.3.0rc1
5.3.1
5.3.1rc1
5.4.0
5.4.0rc1
5.5.0
5.5.0rc1
5.5.1
5.5.1rc1
5.5.2
5.5.2rc1
5.5.2rc2
5.5.3
5.5.3rc1
5.5.4
5.5.4rc1
5.6.0
5.6.0rc1
5.6.1
5.6.1rc1
5.6.2
5.6.2rc1
5.6.3
5.6.3rc1
5.7.0
5.7.0rc1
5.7.1
5.7.1rc1
5.7.2
5.7.2rc1
5.7.3
5.7.3rc1
5.7.4
5.7.4rc1
6.0.0
6.0.0rc1
6.0.0rc2
6.1.0
6.1.0rc1
6.2.0rc1
Fixed in
6.2.0
References Updated Jul 07, 2026 · Source: OSV.dev |
6.0.0rc2
pre
Dependencies (10)
+ 2 more |
|
6.0.0rc1
pre
1 CVE
CVE-2025-27018
PYSEC-2026-1151
GHSA-hhm6-jjf4-6pm3
Jul 07, 2026
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Medium
Network
Low
Low
None
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.1
1.0.1rc1
1.0.2
1.0.2rc1
1.1.0
1.1.0rc1
2.0.0
2.0.0rc1
+ 89 more Show less
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.1.1
2.1.1rc1
2.2.0
2.2.0rc1
2.2.0rc2
2.2.1
2.2.1rc1
2.2.2
2.2.2rc1
2.2.3
2.2.3rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.0rc1
3.2.0
3.2.0rc1
3.2.0rc2
3.2.0rc3
3.2.1
3.2.1rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc2
3.4.0rc3
4.0.0
4.0.0rc1
4.0.1
4.0.1rc1
4.0.2
4.0.2rc1
5.0.0
5.0.0rc1
5.1.0
5.1.0rc1
5.1.0rc2
5.1.1
5.1.1rc1
5.2.0
5.2.0rc1
5.2.1
5.2.1rc1
5.3.0
5.3.0rc1
5.3.1
5.3.1rc1
5.4.0
5.4.0rc1
5.5.0
5.5.0rc1
5.5.1
5.5.1rc1
5.5.2
5.5.2rc1
5.5.2rc2
5.5.3
5.5.3rc1
5.5.4
5.5.4rc1
5.6.0
5.6.0rc1
5.6.1
5.6.1rc1
5.6.2
5.6.2rc1
5.6.3
5.6.3rc1
5.7.0
5.7.0rc1
5.7.1
5.7.1rc1
5.7.2
5.7.2rc1
5.7.3
5.7.3rc1
5.7.4
5.7.4rc1
6.0.0
6.0.0rc1
6.0.0rc2
6.1.0
6.1.0rc1
6.2.0rc1
Fixed in
6.2.0
References Updated Jul 07, 2026 · Source: OSV.dev |
6.0.0rc1
pre
Dependencies (10)
+ 2 more |
|
5.7.4
patch
1 CVE
CVE-2025-27018
PYSEC-2026-1151
GHSA-hhm6-jjf4-6pm3
Jul 07, 2026
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Medium
Network
Low
Low
None
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.1
1.0.1rc1
1.0.2
1.0.2rc1
1.1.0
1.1.0rc1
2.0.0
2.0.0rc1
+ 89 more Show less
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.1.1
2.1.1rc1
2.2.0
2.2.0rc1
2.2.0rc2
2.2.1
2.2.1rc1
2.2.2
2.2.2rc1
2.2.3
2.2.3rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.0rc1
3.2.0
3.2.0rc1
3.2.0rc2
3.2.0rc3
3.2.1
3.2.1rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc2
3.4.0rc3
4.0.0
4.0.0rc1
4.0.1
4.0.1rc1
4.0.2
4.0.2rc1
5.0.0
5.0.0rc1
5.1.0
5.1.0rc1
5.1.0rc2
5.1.1
5.1.1rc1
5.2.0
5.2.0rc1
5.2.1
5.2.1rc1
5.3.0
5.3.0rc1
5.3.1
5.3.1rc1
5.4.0
5.4.0rc1
5.5.0
5.5.0rc1
5.5.1
5.5.1rc1
5.5.2
5.5.2rc1
5.5.2rc2
5.5.3
5.5.3rc1
5.5.4
5.5.4rc1
5.6.0
5.6.0rc1
5.6.1
5.6.1rc1
5.6.2
5.6.2rc1
5.6.3
5.6.3rc1
5.7.0
5.7.0rc1
5.7.1
5.7.1rc1
5.7.2
5.7.2rc1
5.7.3
5.7.3rc1
5.7.4
5.7.4rc1
6.0.0
6.0.0rc1
6.0.0rc2
6.1.0
6.1.0rc1
6.2.0rc1
Fixed in
6.2.0
References Updated Jul 07, 2026 · Source: OSV.dev |
5.7.4
patch
Dependencies (9)
+ 1 more |
|
5.7.4rc1
pre
1 CVE
CVE-2025-27018
PYSEC-2026-1151
GHSA-hhm6-jjf4-6pm3
Jul 07, 2026
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Medium
Network
Low
Low
None
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.1
1.0.1rc1
1.0.2
1.0.2rc1
1.1.0
1.1.0rc1
2.0.0
2.0.0rc1
+ 89 more Show less
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.1.1
2.1.1rc1
2.2.0
2.2.0rc1
2.2.0rc2
2.2.1
2.2.1rc1
2.2.2
2.2.2rc1
2.2.3
2.2.3rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.0rc1
3.2.0
3.2.0rc1
3.2.0rc2
3.2.0rc3
3.2.1
3.2.1rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc2
3.4.0rc3
4.0.0
4.0.0rc1
4.0.1
4.0.1rc1
4.0.2
4.0.2rc1
5.0.0
5.0.0rc1
5.1.0
5.1.0rc1
5.1.0rc2
5.1.1
5.1.1rc1
5.2.0
5.2.0rc1
5.2.1
5.2.1rc1
5.3.0
5.3.0rc1
5.3.1
5.3.1rc1
5.4.0
5.4.0rc1
5.5.0
5.5.0rc1
5.5.1
5.5.1rc1
5.5.2
5.5.2rc1
5.5.2rc2
5.5.3
5.5.3rc1
5.5.4
5.5.4rc1
5.6.0
5.6.0rc1
5.6.1
5.6.1rc1
5.6.2
5.6.2rc1
5.6.3
5.6.3rc1
5.7.0
5.7.0rc1
5.7.1
5.7.1rc1
5.7.2
5.7.2rc1
5.7.3
5.7.3rc1
5.7.4
5.7.4rc1
6.0.0
6.0.0rc1
6.0.0rc2
6.1.0
6.1.0rc1
6.2.0rc1
Fixed in
6.2.0
References Updated Jul 07, 2026 · Source: OSV.dev |
5.7.4rc1
pre
Dependencies (9)
+ 1 more |
|
5.7.3
patch
1 CVE
CVE-2025-27018
PYSEC-2026-1151
GHSA-hhm6-jjf4-6pm3
Jul 07, 2026
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Medium
Network
Low
Low
None
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.1
1.0.1rc1
1.0.2
1.0.2rc1
1.1.0
1.1.0rc1
2.0.0
2.0.0rc1
+ 89 more Show less
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.1.1
2.1.1rc1
2.2.0
2.2.0rc1
2.2.0rc2
2.2.1
2.2.1rc1
2.2.2
2.2.2rc1
2.2.3
2.2.3rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.0rc1
3.2.0
3.2.0rc1
3.2.0rc2
3.2.0rc3
3.2.1
3.2.1rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc2
3.4.0rc3
4.0.0
4.0.0rc1
4.0.1
4.0.1rc1
4.0.2
4.0.2rc1
5.0.0
5.0.0rc1
5.1.0
5.1.0rc1
5.1.0rc2
5.1.1
5.1.1rc1
5.2.0
5.2.0rc1
5.2.1
5.2.1rc1
5.3.0
5.3.0rc1
5.3.1
5.3.1rc1
5.4.0
5.4.0rc1
5.5.0
5.5.0rc1
5.5.1
5.5.1rc1
5.5.2
5.5.2rc1
5.5.2rc2
5.5.3
5.5.3rc1
5.5.4
5.5.4rc1
5.6.0
5.6.0rc1
5.6.1
5.6.1rc1
5.6.2
5.6.2rc1
5.6.3
5.6.3rc1
5.7.0
5.7.0rc1
5.7.1
5.7.1rc1
5.7.2
5.7.2rc1
5.7.3
5.7.3rc1
5.7.4
5.7.4rc1
6.0.0
6.0.0rc1
6.0.0rc2
6.1.0
6.1.0rc1
6.2.0rc1
Fixed in
6.2.0
References Updated Jul 07, 2026 · Source: OSV.dev |
5.7.3
patch
Dependencies (9)
+ 1 more |
|
5.7.3rc1
pre
1 CVE
CVE-2025-27018
PYSEC-2026-1151
GHSA-hhm6-jjf4-6pm3
Jul 07, 2026
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Medium
Network
Low
Low
None
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.1
1.0.1rc1
1.0.2
1.0.2rc1
1.1.0
1.1.0rc1
2.0.0
2.0.0rc1
+ 89 more Show less
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.1.1
2.1.1rc1
2.2.0
2.2.0rc1
2.2.0rc2
2.2.1
2.2.1rc1
2.2.2
2.2.2rc1
2.2.3
2.2.3rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.0rc1
3.2.0
3.2.0rc1
3.2.0rc2
3.2.0rc3
3.2.1
3.2.1rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc2
3.4.0rc3
4.0.0
4.0.0rc1
4.0.1
4.0.1rc1
4.0.2
4.0.2rc1
5.0.0
5.0.0rc1
5.1.0
5.1.0rc1
5.1.0rc2
5.1.1
5.1.1rc1
5.2.0
5.2.0rc1
5.2.1
5.2.1rc1
5.3.0
5.3.0rc1
5.3.1
5.3.1rc1
5.4.0
5.4.0rc1
5.5.0
5.5.0rc1
5.5.1
5.5.1rc1
5.5.2
5.5.2rc1
5.5.2rc2
5.5.3
5.5.3rc1
5.5.4
5.5.4rc1
5.6.0
5.6.0rc1
5.6.1
5.6.1rc1
5.6.2
5.6.2rc1
5.6.3
5.6.3rc1
5.7.0
5.7.0rc1
5.7.1
5.7.1rc1
5.7.2
5.7.2rc1
5.7.3
5.7.3rc1
5.7.4
5.7.4rc1
6.0.0
6.0.0rc1
6.0.0rc2
6.1.0
6.1.0rc1
6.2.0rc1
Fixed in
6.2.0
References Updated Jul 07, 2026 · Source: OSV.dev |
5.7.3rc1
pre
Dependencies (9)
+ 1 more |
|
5.7.2
patch
1 CVE
CVE-2025-27018
PYSEC-2026-1151
GHSA-hhm6-jjf4-6pm3
Jul 07, 2026
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Medium
Network
Low
Low
None
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue. Affected versions
1.0.0
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.1
1.0.1rc1
1.0.2
1.0.2rc1
1.1.0
1.1.0rc1
2.0.0
2.0.0rc1
+ 89 more Show less
2.0.0rc2
2.1.0
2.1.0rc1
2.1.0rc2
2.1.1
2.1.1rc1
2.2.0
2.2.0rc1
2.2.0rc2
2.2.1
2.2.1rc1
2.2.2
2.2.2rc1
2.2.3
2.2.3rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.1.0
3.1.0rc1
3.2.0
3.2.0rc1
3.2.0rc2
3.2.0rc3
3.2.1
3.2.1rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc2
3.4.0rc3
4.0.0
4.0.0rc1
4.0.1
4.0.1rc1
4.0.2
4.0.2rc1
5.0.0
5.0.0rc1
5.1.0
5.1.0rc1
5.1.0rc2
5.1.1
5.1.1rc1
5.2.0
5.2.0rc1
5.2.1
5.2.1rc1
5.3.0
5.3.0rc1
5.3.1
5.3.1rc1
5.4.0
5.4.0rc1
5.5.0
5.5.0rc1
5.5.1
5.5.1rc1
5.5.2
5.5.2rc1
5.5.2rc2
5.5.3
5.5.3rc1
5.5.4
5.5.4rc1
5.6.0
5.6.0rc1
5.6.1
5.6.1rc1
5.6.2
5.6.2rc1
5.6.3
5.6.3rc1
5.7.0
5.7.0rc1
5.7.1
5.7.1rc1
5.7.2
5.7.2rc1
5.7.3
5.7.3rc1
5.7.4
5.7.4rc1
6.0.0
6.0.0rc1
6.0.0rc2
6.1.0
6.1.0rc1
6.2.0rc1
Fixed in
6.2.0
References Updated Jul 07, 2026 · Source: OSV.dev |
5.7.2
patch
Dependencies (9)
+ 1 more |