PT-2026-25891 · Apache · Apache Airflow

Pierre Jeambrun

·

Publicado

2026-03-17

·

Atualizado

2026-03-18

·

CVE-2026-26929

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions 3.0.0 through 3.1.7
Description The FastAPI DagVersion listing API in Apache Airflow does not enforce per-DAG authorization filtering when a request is made with the dag id parameter set to '~' (wildcard for all DAGs). This allows the retrieval of version metadata for DAGs that the requesting user is not authorized to access.
Recommendations Upgrade to Apache Airflow version 3.1.8 or later.

Correção

DoS

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05612
BIT-AIRFLOW-2026-26929
CVE-2026-26929
GHSA-4M3H-WP5W-5HQH
PYSEC-2026-14

Produtos afetados

Apache Airflow