Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-15
10 active CVEs reported via OSV.dev
Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
Apache Airflow Execution with Unnecessary Privileges
Apache Airflow `/api/v2/dagReports` executes DAG Python in API
Apache Airflow Incorrect Authorization vulnerability
Apache Airflow vulnerable to sensitive information exposure
Apache Airflow Improper Input Validation vulnerability
Apache Airflow may allow authenticated users who have been deactivated to continue using the UI or API
Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
OS Command injection in Apache Airflow
Cross-site Scripting in Apache Airflow
Other Workflow projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Apache Airflow โ without relying on volunteer maintainers.
Talk to an Expert โ