Known vulnerabilities in Apache Airflow 1.10.7

Version: 1.10.7
Software CPE: cpe:2.3:a:apache_foundation:apache_airflow:*:*:*:*:*:*:*:*
Total vulnerabilities: 42
Public exploits: 3
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Apache Airflow version 1.10.7 Apache Airflow 1.10.7 is affected by 42 vulnerabilities: 3 high, 9 medium, 30 low Critical High Medium Low

Vulnerabilities (42)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU145333 - Improper Access Control
CVE-2026-40690
CWE-284 Low
No
No
3.2.1 25.08.2026 SB20260825108
#VU145332 - Improper Access Control
CVE-2026-38743
CWE-284 Low
No
No
3.2.1 25.08.2026 SB20260825108
#VU145329 - Deserialization of Untrusted Data
CVE-2026-25917
CWE-502 Low
No
No
3.2.0 25.08.2026 SB20260825102
#VU145327 - Command injection
CVE-2026-30898
CWE-77 Low
No
No
3.2.0 25.08.2026 SB20260825102
#VU145325 - Information Exposure Through an Error Message
CVE-2026-30912
CWE-209 Medium
No
No
3.2.0 25.08.2026 SB20260825102
#VU145322 - Deserialization of Untrusted Data
CVE-2025-54550
CWE-502 Medium
No
No
3.2.0 25.08.2026 SB20260825102
#VU144884 - Improper Access Control
CVE-2026-68076
CWE-284 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144883 - Improper Authorization
CVE-2026-68971
CWE-285 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144881 - Information Exposure Through Log Files
CVE-2026-68970
CWE-532 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144880 - Information Exposure Through Log Files
CVE-2026-68969
CWE-532 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144879 - Incorrect Authorization
CVE-2026-68968
CWE-863 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144875 - Exposure of sensitive information to an unauthorized actor
CVE-2026-54183
CWE-200 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144874 - Deserialization of Untrusted Data
CVE-2026-59242
CWE-502 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144873 - Exposure of sensitive information to an unauthorized actor
CVE-2026-59244
CWE-200 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144869 - Exposure of sensitive information to an unauthorized actor
CVE-2026-48892
CWE-200 Low
No
No
3.3.0 24.08.2026 SB20260824159
#VU144868 - Exposure of sensitive information to an unauthorized actor
CVE-2026-48891
CWE-200 Low
No
No
3.3.0 24.08.2026 SB20260824159
#VU144865 - Improper Access Control
CVE-2026-48828
CWE-284 Low
No
No
3.2.2, 3.3.0 24.08.2026 SB2026060498
#VU144864 - Exposure of sensitive information to an unauthorized actor
CVE-2026-49487
CWE-200 Low
No
No
3.3.0 24.08.2026 SB20260824159
#VU144863 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-33264
CWE-94 Medium
No
No
3.3.0 24.08.2026 SB20260824159
#VU96463 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-41937
CWE-79 Low
No
No
2.10.0 22.08.2024 SB2024082283


Showing elements 1 - 20 out of 42