CVE security advisories and vulnerability history for airflow by apache.
163
Total CVEs
Published
2
In CISA KEV
Exploited in the wild
3
Public exploits
With known exploit
7.1
Avg CVSS
2018–2026
Last updated
Overview
apache airflow has 163 published CVE records since 2018, of which 2 are in CISA's Known Exploited Vulnerabilities catalog and 3 have a known public exploit. The average CVSS base score across scored CVEs is 7.1.
This page aggregates every publicly disclosed vulnerability (CVE) affecting apache airflow, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of apache airflow's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical17
High44
Medium45
Low4
53 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
2
2 of apache airflow's CVEs are confirmed exploited in the wild.
Public exploits
3
3 of apache airflow's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every apache airflow version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about apache airflow vulnerabilities.
How many CVEs does apache airflow have?
apache airflow has 163 published CVE records since 2018.
How many apache airflow CVEs are in CISA KEV?
Yes — 2 of apache airflow's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for apache airflow vulnerabilities?
Yes — 3 of apache airflow's CVEs have a known public exploit.
Which versions of apache airflow are affected?
8,410 distinct apache airflow versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in apache airflow CVEs?
apache airflow's CVEs most often map to these CWE weakness types: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), CWE-20 (Improper Input Validation), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')).
How many critical apache airflow vulnerabilities are there?
apache airflow has 17 critical and 44 high-severity CVEs.
What is the average severity of apache airflow CVEs?
The average CVSS base score across apache airflow's scored CVEs is 7.1.