airflow-3

Direct Vulnerabilities

Known vulnerabilities in the airflow-3 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-9x8q-7h8h-wcw9

<3.2.2-r7
  • L
Improper Initialization

<3.2.2-r7
  • L
GHSA-2fqr-mr3j-6wp8

<3.2.2-r7
  • L
Allocation of Resources Without Limits or Throttling

<3.2.2-r7
  • L
Improper Resource Shutdown or Release

<3.2.2-r7
  • L
Information Exposure

<3.2.2-r7
  • L
GHSA-xcgm-r5h9-7989

<3.2.2-r7
  • L
Allocation of Resources Without Limits or Throttling

<3.2.2-r7
  • L
Improper Handling of Highly Compressed Data (Data Amplification)

<3.2.2-r7
  • L
GHSA-4fvr-rgm6-gqmc

<3.2.2-r7
  • H
HTTP Request Smuggling

<3.2.0-r0
  • L
GHSA-63hw-fmq6-xxg2

<3.2.2-r7
  • L
GHSA-wj6h-64fc-37mp

<3.2.2-r0
  • L
GHSA-vc5p-v9hr-52mj

<3.2.0-r0
  • H
Information Exposure

<3.2.2-r0
  • L
GHSA-hpj7-wq8m-9hgp

<3.2.2-r7
  • L
GHSA-q279-jhrf-cc6v

<3.2.0-r0
  • L
Allocation of Resources Without Limits or Throttling

<3.2.2-r7
  • L
GHSA-4m7w-qmgq-4wj5

<3.2.2-r7
  • L
Algorithmic Complexity

<3.2.0-r0
  • M
Improper Certificate Validation

<3.2.0-r0
  • L
Improper Validation of Certificate with Host Mismatch

<3.2.2-r7
  • L
Arbitrary Code Injection

<3.2.0-r0
  • L
GHSA-g3cq-j2xw-wf74

<3.2.2-r7
  • L
GHSA-7f5h-v6xp-fcq8

<3.2.0-r0
  • L
GHSA-j288-q9x7-2f5v

<3.2.0-r0
  • L
GHSA-9548-qrrj-x5pj

<3.2.0-r0
  • L
Uncontrolled Recursion

<3.2.0-r0
  • L
GHSA-qrc4-49gv-mv9m

<3.2.2-r7
  • L
Authentication Bypass

<3.2.2-r7
  • H
Incorrect Authorization

<3.2.2-r7
  • L
GHSA-v4p8-mg3p-g94g

<3.2.2-r7
  • L
GHSA-vffw-93wf-4j4q

<3.2.2-r7
  • C
SQL Injection

<3.2.2-r7
  • L
GHSA-qf38-jq28-3ccq

<3.2.2-r7
  • L
GHSA-wxxx-gvqv-xp7p

<3.2.2-r7
  • L
Interpretation Conflict

<3.2.2-r7
  • L
Directory Traversal

<3.2.2-r7
  • L
GHSA-4xgf-cpjx-pc3j

<3.2.2-r7
  • L
GHSA-6jv3-5f52-599m

<3.2.2-r7
  • H
Improper Neutralization of Special Elements Used in a Template Engine

<3.2.2-r7
  • L
GHSA-4xpc-pv4p-pm3w

<3.2.2-r7
  • L
Improper Validation of Specified Quantity in Input

<3.2.2-r7
  • L
Resource Exhaustion

<3.2.2-r7
  • L
GHSA-r75f-5x8p-qvmc

<3.2.2-r7
  • H
Incorrect Authorization

<3.2.2-r7
  • L
Improper Input Validation

<3.2.2-r7
  • H
Arbitrary Command Injection

<3.2.2-r7
  • L
GHSA-xqmj-j6mv-4862

<3.2.2-r7
  • L
GHSA-wpfp-gwwc-vwq6

<3.2.2-r7
  • L
Unprotected Alternate Channel

<3.2.2-r7
  • L
GHSA-pw6j-qg29-8w7f

<3.2.2-r7
  • L
GHSA-v9pg-7xvm-68hf

<3.2.2-r7
  • L
GHSA-5rvq-cxj2-64vf

<3.2.2-r7
  • L
GHSA-6v7p-g79w-8964

<3.2.2-r7
  • L
Allocation of Resources Without Limits or Throttling

<3.2.2-r6
  • L
GHSA-82w8-qh3p-5jfq

<3.2.2-r6
  • L
GHSA-jp82-jpqv-5vv3

<3.2.2-r6
  • L
Use of Incorrectly-Resolved Name or Reference

<3.2.2-r6
  • L
GHSA-537c-gmf6-5ccf

<3.2.2-r5
  • L
CVE-2026-49854

<3.2.2-r4
  • L
GHSA-cx3h-4qpv-8hc9

<3.2.2-r4
  • L
GHSA-jg22-mg44-37j8

<3.2.2-r1
  • L
GHSA-hg6j-4rv6-33pg

<3.2.2-r1
  • H
Deserialization of Untrusted Data

<3.2.2-r1
  • H
Origin Validation Error

<3.2.2-r1
  • L
GHSA-g3jr-4jrm-jvqv

<3.2.1-r4
  • M
Information Exposure

<3.2.1-r4
  • L
GHSA-mf9v-mfxr-j63j

<3.2.1-r4
  • L
Information Exposure Through Log Files

<3.2.1-r4
  • L
GHSA-g794-3fmp-753h

<3.2.1-r4
  • L
Improper Certificate Validation

<3.2.1-r4
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<3.2.1-r4
  • L
GHSA-29h4-r29x-hchv

<3.2.1-r4
  • M
Inefficient Regular Expression Complexity

<3.2.1-r4
  • L
CVE-2026-45309

<3.2.1-r4
  • L
CVE-2026-8838

<3.2.1-r4
  • L
GHSA-65pc-fj4g-8rjx

<3.2.1-r4
  • L
GHSA-x8mh-94wc-33gv

<3.2.1-r4
  • L
GHSA-qccp-gfcp-xxvc

<3.2.1-r4
  • L
Allocation of Resources Without Limits or Throttling

<3.2.1-r3
  • L
GHSA-2h4p-vjrc-8xpq

<3.2.1-r3
  • L
Directory Traversal

<3.2.1-r3
  • L
GHSA-pp6c-gr5w-3c5g

<3.2.1-r3
  • L
Open Redirect

<3.2.1-r2
  • L
GHSA-r95x-qfjj-fjj2

<3.2.1-r2
  • L
Use of a Broken or Risky Cryptographic Algorithm

<3.2.1-r2
  • L
GHSA-r374-rxx8-8654

<3.2.1-r2
  • H
Directory Traversal

<3.2.1-r0
  • L
Cross-site Request Forgery (CSRF)

<3.2.1-r0
  • L
GHSA-vfmq-68hx-4jfw

<3.2.1-r1
  • M
Improper Validation of Certificate with Host Mismatch

<3.2.1-r1
  • H
Improper Output Neutralization for Logs

<3.2.1-r1
  • H
Improper Encoding or Escaping of Output

<3.2.1-r1
  • L
GHSA-6hg6-v5c8-fphq

<3.2.1-r1
  • L
GHSA-3pxv-7cmr-fjr4

<3.2.1-r1
  • L
XML External Entity (XXE) Injection

<3.2.1-r1
  • L
GHSA-445c-vh5m-36rj

<3.2.1-r1
  • L
GHSA-68rp-wp8r-4726

<3.2.1-r0
  • L
GHSA-v92g-xgxw-vvmm

<3.2.1-r0
  • L
GHSA-mj87-hwqh-73pj

<3.2.1-r0
  • L
GHSA-72hv-8253-57qq

<3.2.1-r0
  • L
GHSA-jj8c-mmj3-mmgv

<3.2.1-r0
  • L
Resource Exhaustion

<3.2.1-r0
  • M
Information Exposure Through Caching

<3.2.1-r0
  • L
GHSA-p423-j2cm-9vmq

<3.2.0-r1
  • C
Out-of-Bounds

<3.2.0-r1
  • L
GHSA-c92r-g8j5-vhcx

<3.2.0-r0
  • L
GHSA-29vq-49wr-vm6x

<3.2.0-r0
  • L
Exposure of Resource to Wrong Sphere

<3.2.0-r0
  • H
CVE-2026-0994

<3.2.0-r0
  • M
Improper Handling of Windows Device Names

<3.2.0-r0
  • L
GHSA-7gcm-g887-7qv7

<3.2.0-r0
  • L
GHSA-q5fh-2hc8-f6rq

<3.2.0-r0
  • M
Declaration of Catch for Generic Exception

<3.2.0-r0
  • L
GHSA-r7vr-m4jw-r794

<3.2.0-r0
  • L
Insufficient Session Expiration

<3.2.0-r0
  • L
GHSA-hcc4-c3v8-rx92

<3.2.1-r0
  • L
GHSA-2vrm-gr82-f7m5

<3.2.1-r0
  • L
GHSA-54jq-c3m8-4m76

<3.2.0-r0
  • L
Allocation of Resources Without Limits or Throttling

<3.2.1-r0
  • L
GHSA-63hf-3vf5-4wqf

<3.2.1-r0
  • L
GHSA-mwh4-6h8g-pg8w

<3.2.1-r0
  • H
Directory Traversal

<3.2.1-r0
  • M
Directory Traversal

<3.2.0-r0
  • M
HTTP Response Splitting

<3.2.1-r0
  • M
Information Exposure

<3.2.1-r0
  • M
HTTP Response Splitting

<3.2.1-r0
  • L
GHSA-w2fm-2cpv-w7v5

<3.2.1-r0
  • L
GHSA-966j-vmvw-g2g9

<3.2.1-r0
  • M
HTTP Request Smuggling

<3.2.0-r0
  • L
GHSA-pph8-gcv7-4qj5

<3.1.2-r0
  • H
Allocation of Resources Without Limits or Throttling

<3.2.1-r0
  • L
Resource Exhaustion

<3.2.1-r0
  • L
GHSA-p998-jp59-783m

<3.2.1-r0
  • L
Incomplete Blacklist

<3.1.6-r0
  • M
HTTP Request Smuggling

<3.2.0-r0
  • M
Allocation of Resources Without Limits or Throttling

<3.2.0-r0
  • L
GHSA-mrfv-m5wm-5w6w

<3.1.6-r0
  • L
GHSA-m5qp-6w8w-w647

<3.2.1-r0
  • L
GHSA-6mq8-rvhq-8wgg

<3.2.0-r0
  • L
GHSA-fh55-r93g-j68g

<3.2.0-r0
  • L
GHSA-c427-h43c-vf67

<3.2.1-r0
  • M
Improper Input Validation

<3.2.1-r0
  • L
GHSA-g84x-mcqj-x9qq

<3.2.0-r0
  • M
Logging of Excessive Data

<3.2.0-r0
  • H
Allocation of Resources Without Limits or Throttling

<3.2.0-r0
  • L
GHSA-mqqc-3gqh-h2x8

<3.2.0-r0
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<3.2.0-r0
  • M
Allocation of Resources Without Limits or Throttling

<3.2.1-r0
  • L
GHSA-jj3x-wxrx-4x23

<3.2.0-r0
  • L
GHSA-69f9-5gxw-wvc2

<3.2.0-r0
  • L
HTTP Response Splitting

<3.2.1-r0
  • L
GHSA-3wq7-rqq7-wx6j

<3.2.1-r0
  • L
GHSA-6jhg-hg63-jvvf

<3.2.0-r0
  • L
Improper Handling of Highly Compressed Data (Data Amplification)

<3.2.0-r0
  • L
GHSA-53mr-6c8q-9789

<3.1.8-r11
  • H
Incorrect Authorization

<3.1.8-r11
  • L
Improper Authentication

<3.1.8-r11
  • L
GHSA-jjhc-v7c2-5hh6

<3.1.8-r11
  • L
Resource Exhaustion

<3.1.8-r10
  • M
Improper Certificate Validation

<3.1.8-r10
  • L
GHSA-m959-cc7f-wv43

<3.1.8-r10
  • M
Insecure Temporary File

<3.1.8-r10
  • L
GHSA-5239-wwwm-4pmq

<3.1.8-r10
  • L
GHSA-gc5v-m9x4-r6x2

<3.1.8-r10
  • L
GHSA-jr27-m4p2-rc6r

<3.1.8-r9
  • L
Uncontrolled Recursion

<3.1.8-r9
  • L
GHSA-752w-5fwx-jx9f

<3.1.8-r8
  • L
GHSA-vp96-hxj8-p424

<3.1.8-r8
  • L
GHSA-5pwr-322w-8jr4

<3.1.8-r8
  • C
Buffer Overflow

<3.1.8-r8
  • L
Insufficient Verification of Data Authenticity

<3.1.8-r8
  • M
Not Failing Securely ('Failing Open')

<3.1.8-r8
  • H
Resource Exhaustion

<3.1.8-r2
  • L
GHSA-qjxf-f2mg-c6mc

<3.1.8-r2
  • L
GHSA-78cv-mqj4-43f7

<3.1.8-r2
  • L
Origin Validation Error

<3.1.8-r0
  • C
Improper Verification of Cryptographic Signature

<3.1.8-r0
  • L
GHSA-9r5j-7r2x-rv4g

<3.1.8-r0
  • L
Improper Control of Dynamically-Managed Code Resources

<3.1.8-r0
  • L
GHSA-7wc2-qxgw-g8gg

<3.1.8-r0
  • L
GHSA-rv5f-ccpm-xjj4

<3.1.8-r0
  • L
GHSA-r6ph-v2qm-q3c2

<3.1.7-r1
  • M
CVE-2026-26007

<3.1.7-r1
  • L
Incorrect Use of Privileged APIs

<3.1.7-r0
  • L
GHSA-pm44-x5x7-24c4

<3.1.7-r0
  • M
Directory Traversal

<3.1.6-r2
  • L
Allocation of Resources Without Limits or Throttling

<3.1.6-r2
  • L
GHSA-8rrh-rw8j-w5fx

<3.1.6-r2
  • L
GHSA-63vm-454h-vhhq

<3.1.6-r2
  • L
GHSA-wp53-j4wj-2cfg

<3.1.6-r4
  • H
Directory Traversal

<3.1.6-r4
  • L
Directory Traversal

<3.1.6-r2
  • L
GHSA-58pv-8j8x-9vj2

<3.1.6-r2
  • L
Information Exposure Through Log Files

<3.1.6-r0
  • L
GHSA-3qmm-r55x-hpxx

<3.1.6-r0
  • L
GHSA-7c2f-r6gc-h92h

<3.1.6-r0
  • L
Information Exposure

<3.1.6-r0
  • L
GHSA-jm66-cg57-jjv5

<3.1.5-r4
  • L
Link Following

<3.1.5-r4
  • H
Deserialization of Untrusted Data

<3.1.5-r4
  • L
GHSA-qmgc-5h2g-mvrw

<3.1.5-r4
  • L
GHSA-38jv-5279-wg99

<3.1.5-r3
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<3.1.5-r3
  • L
GHSA-hgf8-39gv-g3f2

<3.1.3-r0
  • M
Improper Handling of Windows Device Names

<3.1.3-r0
  • L
Asymmetric Resource Consumption (Amplification)

<3.1.5-r1
  • L
GHSA-428g-f7cq-pgp5

<3.1.5-r1
  • L
GHSA-w853-jp5j-5j7f

<3.1.5-r0
  • M
Link Following

<3.1.5-r0
  • L
GHSA-gm62-xv2j-4w53

<3.1.4-r0
  • L
GHSA-2xpw-w6gg-jr37

<3.1.4-r0
  • H
Allocation of Resources Without Limits or Throttling

<3.1.4-r0
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<3.1.4-r0
  • L
External Control of File Name or Path

<3.1.0-r3
  • L
CRLF Injection

<3.0.6-r0
  • L
Allocation of Resources Without Limits or Throttling

<3.0.3-r3
  • M
Open Redirect

<3.0.2-r2
  • M
Open Redirect

<3.0.2-r2
  • H
Resource Exhaustion

<3.2.0-r0
  • L
GHSA-hrfv-mqp8-q5rw

<3.2.0-r0
  • L
GHSA-2g68-c3qc-8985

<3.2.0-r0
  • L
CVE-2024-34069

<3.2.0-r0
  • H
Out-of-bounds Write

<3.2.0-r0
  • L
Function Call With Incorrect Order of Arguments

<3.0.1-r1
  • L
GHSA-q34m-jh98-gwm2

<3.2.0-r0
  • M
Open Redirect

<3.0.1-r1
  • M
Directory Traversal

<3.2.0-r0
  • L
Insufficiently Protected Credentials

<3.0.1-r1
  • L
GHSA-f9vj-2wh5-fj8j

<3.2.0-r0
  • L
Allocation of Resources Without Limits or Throttling

<3.0.1-r1
  • L
CVE-2025-5279

<3.0.1-r1