oss-security·2d agoCVE-2026-97636: Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key#apache-airflow#hashicorp#vaultCVE-2026-97636
oss-security·5d agoCVE-2026-75158: Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter#apache-airflow#cve-2026-75158#authorizationCVE-2026-75158 3 sources
oss-security·9d agoCVE-2026-75157: Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)#access-control#apache-airflow#authorizationCVE-2026-75157
oss-security·11d agoCVE-2026-86792: Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration#apache-airflow#cve-2026-86792#kafkaCVE-2026-867924
oss-security·11d agoCVE-2026-86465: Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key#access-control#akeyless#apache-airflowCVE-2026-86465
oss-security·11d agoCVE-2026-86466: Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated#apache-airflow#authentication-bypass#authentikCVE-2026-86466 3 sources1
oss-security·11d agoCVE-2026-82310: Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access#access-control#account-deactivation#apache-airflowCVE-2026-82310
oss-security·11d agoCVE-2026-76187: Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT#apache-airflow#authentication-bypass#client-credentialsCVE-2026-76187 2 sources1
oss-security·18d agoCVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass#apache-airflow#authentication-bypass#azure-adCVE-2026-75156