Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-07-17
10 active CVEs reported via OSV.dev
Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
Apache Airflow Execution with Unnecessary Privileges
Apache Airflow `/api/v2/dagReports` executes DAG Python in API
Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra` to read-permitted users
Apache Airflow Incorrect Authorization vulnerability
Apache Airflow Vulnerable to Deserialization of Untrusted Data
Apache Airflow vulnerable to sensitive information exposure
Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Apache Airflow Improper Input Validation vulnerability
Apache Airflow may allow authenticated users who have been deactivated to continue using the UI or API
Get SLA-backed support, security patches, and direct access to senior engineers for Apache Airflow — without relying on volunteer maintainers.