Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25513
Total
1895
Critical
7789
High
8000
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48726 | UNKNOWN | — | A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow … | Jun 01, 2026 |
| CVE-2026-46764 | MEDIUM | 4.3 | The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly by numeric ID after only the generic Audit Log permission check, … | Jun 01, 2026 |
| CVE-2026-46605 | MEDIUM | 4.3 | Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache … | Jun 01, 2026 |
| CVE-2026-45505 | HIGH | 8.8 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such … | Jun 01, 2026 |
| CVE-2026-45426 | LOW | 3.1 | Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log … | Jun 01, 2026 |
| CVE-2026-45360 | UNKNOWN | — | Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary class paths drawn from DAG-author-controlled serialized state without an allowlist or plugin-registry gate. A DAG … | Jun 01, 2026 |
| CVE-2026-44825 | HIGH | 8.1 | Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to … | Jun 01, 2026 |
| CVE-2026-42588 | HIGH | 8.1 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes … | Jun 01, 2026 |
| CVE-2026-42360 | MEDIUM | 6.5 | A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_key` keys inside a JSON … | Jun 01, 2026 |
| CVE-2026-42359 | UNKNOWN | — | A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a Dag to set XCom … | Jun 01, 2026 |
| CVE-2026-42358 | MEDIUM | 6.5 | A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `secret`, `api_key`) to be bypassed when … | Jun 01, 2026 |
| CVE-2026-42253 | MEDIUM | 6.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API … | Jun 01, 2026 |
| CVE-2026-42252 | UNKNOWN | — | Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization … | Jun 01, 2026 |
| CVE-2026-41084 | UNKNOWN | — | A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization against the `dag_id` resolved from the URL path while operating on the … | Jun 01, 2026 |
| CVE-2026-41017 | MEDIUM | 5.9 | Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy (e.g. … | Jun 01, 2026 |
| CVE-2026-41014 | UNKNOWN | — | The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate … | Jun 01, 2026 |
| CVE-2026-40963 | LOW | 3.1 | The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those … | Jun 01, 2026 |
| CVE-2026-40961 | UNKNOWN | — | A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirection from a … | Jun 01, 2026 |
| CVE-2026-40861 | UNKNOWN | — | A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process … | Jun 01, 2026 |
| CVE-2026-40549 | UNKNOWN | — | SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An attacker can craft a malicious website that, when visited … | Jun 01, 2026 |
| CVE-2026-40548 | UNKNOWN | — | SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a legitimate … | Jun 01, 2026 |
| CVE-2026-40547 | UNKNOWN | — | SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow reading … | Jun 01, 2026 |
| CVE-2026-40546 | UNKNOWN | — | SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inject arbitrary SQL commands, potentially gaining full control over … | Jun 01, 2026 |
| CVE-2026-40545 | UNKNOWN | — | SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in … | Jun 01, 2026 |
| CVE-2026-40544 | UNKNOWN | — | SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated attacker with access to the backup functionality can upload a crafted ZIP … | Jun 01, 2026 |