Known vulnerabilities in Apache Airflow 2.0.1

Version: 2.0.1
Software CPE: cpe:2.3:a:apache_foundation:apache_airflow:*:*:*:*:*:*:*:*
Total vulnerabilities: 53
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Apache Airflow version 2.0.1 Apache Airflow 2.0.1 is affected by 53 vulnerabilities: 3 high, 9 medium, 41 low Critical High Medium Low

Vulnerabilities (53)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU145333 - Improper Access Control
CVE-2026-40690
CWE-284 Low
No
No
3.2.1 25.08.2026 SB20260825108
#VU145332 - Improper Access Control
CVE-2026-38743
CWE-284 Low
No
No
3.2.1 25.08.2026 SB20260825108
#VU145329 - Deserialization of Untrusted Data
CVE-2026-25917
CWE-502 Low
No
No
3.2.0 25.08.2026 SB20260825102
#VU145327 - Command injection
CVE-2026-30898
CWE-77 Low
No
No
3.2.0 25.08.2026 SB20260825102
#VU145325 - Information Exposure Through an Error Message
CVE-2026-30912
CWE-209 Medium
No
No
3.2.0 25.08.2026 SB20260825102
#VU145322 - Deserialization of Untrusted Data
CVE-2025-54550
CWE-502 Medium
No
No
3.2.0 25.08.2026 SB20260825102
#VU144884 - Improper Access Control
CVE-2026-68076
CWE-284 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144883 - Improper Authorization
CVE-2026-68971
CWE-285 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144881 - Information Exposure Through Log Files
CVE-2026-68970
CWE-532 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144880 - Information Exposure Through Log Files
CVE-2026-68969
CWE-532 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144879 - Incorrect Authorization
CVE-2026-68968
CWE-863 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144875 - Exposure of sensitive information to an unauthorized actor
CVE-2026-54183
CWE-200 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144874 - Deserialization of Untrusted Data
CVE-2026-59242
CWE-502 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144873 - Exposure of sensitive information to an unauthorized actor
CVE-2026-59244
CWE-200 Low
No
No
3.3.1 24.08.2026 SB20260824160
#VU144869 - Exposure of sensitive information to an unauthorized actor
CVE-2026-48892
CWE-200 Low
No
No
3.3.0 24.08.2026 SB20260824159
#VU144868 - Exposure of sensitive information to an unauthorized actor
CVE-2026-48891
CWE-200 Low
No
No
3.3.0 24.08.2026 SB20260824159
#VU144865 - Improper Access Control
CVE-2026-48828
CWE-284 Low
No
No
3.2.2, 3.3.0 24.08.2026 SB2026060498
#VU144864 - Exposure of sensitive information to an unauthorized actor
CVE-2026-49487
CWE-200 Low
No
No
3.3.0 24.08.2026 SB20260824159
#VU144863 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-33264
CWE-94 Medium
No
No
3.3.0 24.08.2026 SB20260824159
#VU133378 - Improper Certificate Validation
CVE-2026-49267
CWE-295 Medium
No
No
3.2.2 04.06.2026 SB2026060498


Showing elements 1 - 20 out of 53