Airflow
Vendor:
First CVE: Aug 6, 2018 · Active for 7 years
144
Total CVEs
More Total CVEs than 99% of tracked products
16.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
1.4%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Airflow over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2018
7 years ago
Most Recent CVE
Jul 7, 2026
17 days ago
CVE Severity & Scoring
Airflow144 CVEs
60%
28%
10%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (3.5%)
Network139 (96.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low135 (93.8%)
High9 (6.3%)
Unknown0 (0.0%)
User Interaction
None118 (81.9%)
Unknown0 (0.0%)
Required26 (18.1%)
Privileges Required
Low81 (56.3%)
High7 (4.9%)
None56 (38.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (144 CVEs).
144 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13927CRITICAL The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Ai | Nov 10, 2020 | 9.8 | 99 | YES | YES |
CVE-2020-11978HIGH An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which | Jul 17, 2020 | 8.8 | 98 | YES | YES |
CVE-2021-38540CRITICAL The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables | Sep 9, 2021 | 9.8 | 82 | NO | YES |
CVE-2022-24288HIGH In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI. | Feb 25, 2022 | 8.8 | 80 | NO | YES |
CVE-2022-40127HIGH A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This | Nov 14, 2022 | 8.8 | 77 | NO | YES |
CVE-2022-45402MEDIUM In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint. | Nov 15, 2022 | 6.1 | 58 | NO | NO |
CVE-2020-11981CRITICAL An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to i | Jul 17, 2020 | 9.8 | 53 | NO | YES |
CVE-2026-33264CRITICAL A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG | Jul 7, 2026 | 9.8 | 44 | NO | NO |
CVE-2020-17526HIGH Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to acce | Dec 21, 2020 | 7.7 | 40 | NO | YES |
CVE-2023-22884CRITICAL Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Ai | Jan 21, 2023 | 9.8 | 37 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (144 CVEs).
CISA KEV
2 CVEs
1.4% of CVEs· 96th percentile
Metasploit
2 CVEs
1.4% of CVEs· 96th percentile
Nuclei
7 CVEs
4.9% of CVEs· 97th percentile
ExploitDB
2 CVEs
1.4% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (144 CVEs).
Media Mentions
Signals from CVEs in this product scope (144 CVEs).
Top CNAs Publishing CVEs For Airflow
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.3 | 1 | 6.5 | 0.9% | 0 | 0 |
| 2.9.0 | 1 | 5.4 | 1.6% | 0 | 0 |
| 2.10.0 | 1 | 8.8 | 1.2% | 0 | 0 |
| 2.0.0 | 2 | 5.9 | 3.7% | 0 | 0 |
| 1.10.0 | 1 | 5.3 | 3.4% | 0 | 0 |