PT-2026-21670 · Apache · Apache Airflow

Seokchan Yoon

·

Published

2026-02-24

·

Updated

2026-03-01

·

CVE-2024-56373

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 2.11.1
Description A user with DAG author permissions can manipulate the Airflow database to execute arbitrary code within the web server context. This could lead to remote code execution on the server-side when a user views historical task information. The functionality responsible for this issue, log template history, is disabled by default in version 2.11.1. The issue involves Server-Side Template Injection (SSTI) through shared database information.
Recommendations Upgrade to Airflow version 2.11.1 or later. If you require log template history, upgrade to Airflow 3. Manually modify historical log file names if you need to view logs generated before the last log template change.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2024-56373
CVE-2024-56373
GHSA-R837-HPV7-PC2F

Affected Products

Apache Airflow