airflow-2

Direct Vulnerabilities

Known vulnerabilities in the airflow-2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-pjwm-pj3p-43mv

<2.11.2-r12
  • L
Server-Side Request Forgery (SSRF)

<2.11.2-r12
  • L
Authentication Bypass

<2.11.2-r12
  • L
GHSA-4xpc-pv4p-pm3w

<2.11.2-r12
  • L
GHSA-j86x-fwp2-qh7v

<2.11.2-r11
  • L
Information Exposure Through Log Files

<2.11.2-r11
  • H
Directory Traversal

<2.11.2-r9
  • L
Cross-site Request Forgery (CSRF)

<2.11.2-r8
  • L
GHSA-mj87-hwqh-73pj

<2.11.2-r9
  • L
Resource Exhaustion

<2.11.2-r9
  • L
CVE-2026-1703

<2.11.2-r9
  • L
GHSA-6vgw-5pg2-w6jp

<2.11.2-r9
  • L
GHSA-v92g-xgxw-vvmm

<2.11.2-r9
  • L
GHSA-p423-j2cm-9vmq

<2.11.2-r8
  • C
Out-of-Bounds

<2.11.2-r8
  • L
GHSA-pjjw-68hj-v9mw

<2.11.2-r8
  • L
GHSA-jj8c-mmj3-mmgv

<2.11.2-r8
  • L
GHSA-69x8-hrgq-fjj8

<2.11.2-r7
  • L
GHSA-53mr-6c8q-9789

<2.11.2-r7
  • L
Improper Authentication

<2.11.2-r7
  • L
GHSA-jjhc-v7c2-5hh6

<2.11.2-r7
  • H
Incorrect Authorization

<2.11.2-r7
  • L
GHSA-m5qp-6w8w-w647

<2.11.2-r5
  • L
Resource Exhaustion

<2.11.2-r5
  • M
HTTP Response Splitting

<2.11.2-r5
  • L
GHSA-mwh4-6h8g-pg8w

<2.11.2-r5
  • L
GHSA-hcc4-c3v8-rx92

<2.11.2-r5
  • M
Information Exposure Through Caching

<2.11.2-r5
  • H
Directory Traversal

<2.11.2-r5
  • L
GHSA-f9vj-2wh5-fj8j

<2.11.1-r0
  • H
Information Exposure

<2.11.2-r5
  • L
CVE-2024-34069

<2.11.1-r0
  • L
Allocation of Resources Without Limits or Throttling

<2.11.2-r5
  • M
Allocation of Resources Without Limits or Throttling

<2.11.2-r5
  • L
GHSA-q34m-jh98-gwm2

<2.11.1-r0
  • H
Out-of-bounds Write

<2.11.1-r0
  • L
GHSA-hrfv-mqp8-q5rw

<2.11.1-r0
  • L
GHSA-w2fm-2cpv-w7v5

<2.11.2-r5
  • M
Directory Traversal

<2.11.1-r0
  • L
GHSA-mrfv-m5wm-5w6w

<2.11.1-r0
  • L
GHSA-2g68-c3qc-8985

<2.11.1-r0
  • L
GHSA-63hf-3vf5-4wqf

<2.11.2-r5
  • L
GHSA-wj6h-64fc-37mp

<2.11.2-r5
  • L
GHSA-966j-vmvw-g2g9

<2.11.2-r5
  • M
HTTP Response Splitting

<2.11.2-r5
  • L
GHSA-p998-jp59-783m

<2.11.2-r5
  • L
GHSA-c427-h43c-vf67

<2.11.2-r5
  • M
Information Exposure

<2.11.2-r5
  • H
Resource Exhaustion

<2.11.1-r0
  • H
Allocation of Resources Without Limits or Throttling

<2.11.2-r5
  • L
Incomplete Blacklist

<2.11.1-r0
  • L
GHSA-3wq7-rqq7-wx6j

<2.11.2-r5
  • M
Improper Input Validation

<2.11.2-r5
  • L
GHSA-68rp-wp8r-4726

<2.11.2-r5
  • L
GHSA-2vrm-gr82-f7m5

<2.11.2-r5
  • L
HTTP Response Splitting

<2.11.2-r5
  • M
CVE-2026-26007

<2.11.2-r5
  • L
GHSA-m959-cc7f-wv43

<2.11.2-r5
  • L
Improper Input Validation

<2.11.2-r5
  • L
GHSA-9f5j-8jwj-x28g

<2.11.2-r5
  • M
Insecure Temporary File

<2.11.2-r5
  • L
GHSA-gc5v-m9x4-r6x2

<2.11.2-r5
  • L
GHSA-r6ph-v2qm-q3c2

<2.11.2-r5
  • M
Improper Certificate Validation

<2.11.2-r5
  • L
GHSA-jr27-m4p2-rc6r

<2.11.2-r3
  • L
GHSA-5239-wwwm-4pmq

<2.11.2-r4
  • L
Resource Exhaustion

<2.11.2-r4
  • L
Uncontrolled Recursion

<2.11.2-r3
  • L
GHSA-752w-5fwx-jx9f

<2.11.2-r2
  • L
GHSA-vp96-hxj8-p424

<2.11.2-r2
  • M
Not Failing Securely ('Failing Open')

<2.11.2-r2
  • L
GHSA-5pwr-322w-8jr4

<2.11.2-r2
  • C
Buffer Overflow

<2.11.2-r2
  • L
Insufficient Verification of Data Authenticity

<2.11.2-r2
  • L
GHSA-qjxf-f2mg-c6mc

<2.11.2-r1
  • L
GHSA-78cv-mqj4-43f7

<2.11.2-r1
  • H
Resource Exhaustion

<2.11.2-r1
  • L
Improper Control of Dynamically-Managed Code Resources

<2.11.2-r0
  • L
GHSA-9r5j-7r2x-rv4g

<2.11.2-r0
  • L
Origin Validation Error

<2.11.1-r1
  • L
GHSA-rv5f-ccpm-xjj4

<2.11.1-r1
  • L
Information Exposure

<2.11.1-r0
  • L
Information Exposure Through Log Files

<2.11.1-r0
  • L
GHSA-8r55-rv5w-6pfm

<2.11.1-r0
  • L
Arbitrary Code Injection

<2.11.1-r0
  • L
GHSA-7c2f-r6gc-h92h

<2.11.1-r0
  • L
Information Exposure Through Log Files

<2.11.1-r0
  • L
GHSA-7gcm-g887-7qv7

<2.11.1-r0
  • H
CVE-2026-0994

<2.11.1-r0
  • M
Improper Handling of Windows Device Names

<2.11.1-r0
  • L
GHSA-r837-hpv7-pc2f

<2.11.1-r0
  • L
GHSA-29vq-49wr-vm6x

<2.11.1-r0
  • L
GHSA-gfw7-2v73-69wg

<2.11.1-r0
  • L
GHSA-wh2j-26j7-9728

<2.11.0-r28
  • L
CVE-2026-2473

<2.11.0-r28
  • L
GHSA-27jp-wm6q-gp25

<2.11.0-r26
  • M
Server-Side Request Forgery (SSRF)

<2.11.0-r15
  • L
GHSA-3xgq-45jj-v275

<2.11.0-r15
  • L
GHSA-m5xw-hwxw-fq3j

<2.11.0-r15
  • H
Server-Side Request Forgery (SSRF)

<2.11.0-r15
  • H
Insufficient Entropy

<2.11.0-r15
  • L
Allocation of Resources Without Limits or Throttling

<2.11.0-r15
  • L
GHSA-jr5f-v2jv-69x6

<2.11.0-r15
  • L
GHSA-chg9-3c3p-ch23

<2.11.0-r15
  • L
GHSA-8hc4-vh64-cxmj

<2.11.0-r15
  • L
GHSA-4hjh-wcwx-xvwj

<2.11.0-r15
  • L
GHSA-pph8-gcv7-4qj5

<2.11.0-r15
  • L
Deserialization of Untrusted Data

<2.11.0-r15
  • L
CVE-2024-21538

<2.11.0-r15
  • L
GHSA-fjxv-7rqg-78g4

<2.11.0-r15
  • L
CVE-2025-7783

<2.11.0-r15
  • L
GHSA-8rrh-rw8j-w5fx

<2.11.2-r5
  • M
Directory Traversal

<2.11.2-r5
  • L
GHSA-63vm-454h-vhhq

<2.11.0-r24
  • L
Allocation of Resources Without Limits or Throttling

<2.11.0-r24
  • L
GHSA-58pv-8j8x-9vj2

<2.11.0-r22
  • L
Directory Traversal

<2.11.0-r22
  • L
Link Following

<2.11.0-r21
  • L
GHSA-jm66-cg57-jjv5

<2.11.0-r21
  • L
GHSA-qmgc-5h2g-mvrw

<2.11.0-r21
  • H
Deserialization of Untrusted Data

<2.11.0-r21
  • L
GHSA-38jv-5279-wg99

<2.11.0-r20
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<2.11.0-r20
  • M
Allocation of Resources Without Limits or Throttling

<2.11.0-r19
  • M
HTTP Request Smuggling

<2.11.0-r19
  • M
HTTP Request Smuggling

<2.11.0-r19
  • L
GHSA-fh55-r93g-j68g

<2.11.0-r19
  • L
GHSA-6jhg-hg63-jvvf

<2.11.0-r19
  • H
Allocation of Resources Without Limits or Throttling

<2.11.0-r19
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<2.11.0-r19
  • L
GHSA-mqqc-3gqh-h2x8

<2.11.0-r19
  • M
Directory Traversal

<2.11.0-r19
  • L
GHSA-jj3x-wxrx-4x23

<2.11.0-r19
  • L
GHSA-69f9-5gxw-wvc2

<2.11.0-r19
  • L
Improper Handling of Highly Compressed Data (Data Amplification)

<2.11.0-r19
  • L
GHSA-g84x-mcqj-x9qq

<2.11.0-r19
  • L
GHSA-6mq8-rvhq-8wgg

<2.11.0-r19
  • M
Logging of Excessive Data

<2.11.0-r19
  • L
GHSA-54jq-c3m8-4m76

<2.11.0-r19
  • L
GHSA-428g-f7cq-pgp5

<2.11.0-r18
  • L
Asymmetric Resource Consumption (Amplification)

<2.11.0-r18
  • M
Link Following

<2.11.0-r17
  • L
GHSA-w853-jp5j-5j7f

<2.11.0-r17
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<2.11.0-r16
  • L
GHSA-gm62-xv2j-4w53

<2.11.0-r16
  • L
GHSA-2xpw-w6gg-jr37

<2.11.0-r16
  • H
Allocation of Resources Without Limits or Throttling

<2.11.0-r16
  • L
External Control of File Name or Path

<2.11.0-r15
  • L
CVE-2025-8869

<2.11.2-r5
  • L
GHSA-4xh5-x5gv-qwph

<2.11.2-r5
  • L
CRLF Injection

<2.11.0-r12
  • M
Open Redirect

<2.11.0-r5
  • M
Open Redirect

<2.11.0-r5