PyPI package intelligence

apache-airflow Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the PyPI package apache-airflow, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
3
Known exploited vulnerabilities affecting apache-airflow
In CISA KEV
2
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
apache-airflow KEVs with sensor-observed exploitation activity

Review apache-airflow exploitation against the versions you run

One of the three exploited apache-airflow vulnerabilities tracked here are not in CISA KEV.

67%
Covered by CISA
33%
Beyond CISA

Attested apache-airflow vulnerabilities

3 known exploited vulnerabilities affecting this package.

Vulnerability CISA KEV Added
CVE-2020-13927

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to...

In CISA 18 Jan 2022
CVE-2020-11978

An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example...

In CISA 18 Jan 2022
CVE-2022-24288

Apache Airflow: RCE in example DAGs

Beyond CISA 25 Feb 2022

Recurring weakness patterns

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Invokable Control Element with Variadic Parameters, and Initialization of a Resource with an Insecure Default account for mapped occurrences across this apache-airflow KEV portfolio.

Browse all KEVs →