Airflow

Vendor:

First CVE: Aug 6, 2018 · Active for 7 years

144
Total CVEs
More Total CVEs than 99% of tracked products
16.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
1.4%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Airflow over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2018
7 years ago
Most Recent CVE
Jul 7, 2026
17 days ago

CVE Severity & Scoring

Airflow144 CVEs
All CVEs352,101 CVEs
LowMediumHighCritical
Attack Vector
Local5 (3.5%)
Network139 (96.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low135 (93.8%)
High9 (6.3%)
Unknown0 (0.0%)
User Interaction
None118 (81.9%)
Unknown0 (0.0%)
Required26 (18.1%)
Privileges Required
Low81 (56.3%)
High7 (4.9%)
None56 (38.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (144 CVEs).

144 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Ai
Nov 10, 20209.899YESYES
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which
Jul 17, 20208.898YESYES
The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables
Sep 9, 20219.882NOYES
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
Feb 25, 20228.880NOYES
A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This
Nov 14, 20228.877NOYES
In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.
Nov 15, 20226.158NONO
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to i
Jul 17, 20209.853NOYES
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG
Jul 7, 20269.844NONO
Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to acce
Dec 21, 20207.740NOYES
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Ai
Jan 21, 20239.837NONO

Exploit Exposure

Signals from CVEs in this product scope (144 CVEs).

CISA KEV
2 CVEs
1.4% of CVEs· 96th percentile
Metasploit
2 CVEs
1.4% of CVEs· 96th percentile
Nuclei
7 CVEs
4.9% of CVEs· 97th percentile
ExploitDB
2 CVEs
1.4% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (144 CVEs).

Media Mentions

Signals from CVEs in this product scope (144 CVEs).

Top CNAs Publishing CVEs For Airflow

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0.316.50.9%00
2.9.015.41.6%00
2.10.018.81.2%00
2.0.025.93.7%00
1.10.015.33.4%00