Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Selen

#40722of 53,625
6.5Total CVSS
Vulnerabilities · 1
PT-2026-31598
6.5
2026-04-09
Apache · Apache Airflow · CVE-2026-34538
Name of the Vulnerable Software and Affected Versions Apache Airflow versions 3.0.0 through 3.1.8 Description The DagRun wait endpoint in Apache Airflow allows users with DAG Run read permissions, such as the Viewer role, to access XCom result values. This behavior contradicts the intended security model where XCom is a protected resource and the Viewer role should be read-only. Recommendations Upgrade to Apache Airflow version 3.2.0.