airflow-2

Direct Vulnerabilities

Known vulnerabilities in the airflow-2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
HTTP Request Smuggling

*
  • L
Resource Exhaustion

*
  • L
HTTP Request Smuggling

*
  • L
Information Exposure

*
  • L
Improper Certificate Validation

*
  • L
Out-of-bounds Read

*
  • L
Improper Input Validation

*
  • L
Resource Exhaustion

*
  • H
Deserialization of Untrusted Data

*
  • L
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • L
Directory Traversal

*
  • L
Improper Authentication

*
  • L
Arbitrary Code Injection

<2.11.2-r0
  • L
External Control of File Name or Path

*
  • L
Resource Exhaustion

*
  • L
GHSA-r7wm-3cxj-wff9

*
  • L
Resource Exhaustion

*
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • L
Resource Exhaustion

<2.11.2-r0
  • M
Cross-site Scripting (XSS)

<2.11.2-r0
  • L
Resource Exhaustion

<2.11.2-r0
  • L
Link Following

*
  • L
Deserialization of Untrusted Data

*
  • L
Resource Exhaustion

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • L
Information Exposure

*
  • L
Resource Exhaustion

*
  • L
Improper Certificate Validation

*
  • M
Information Exposure

*
  • M
CVE-2026-8643

*
  • L
Insufficient Session Expiration

*
  • L
CVE-2026-53533

*
  • L
Information Exposure

*
  • L
Open Redirect

*
  • L
CVE-2026-45361

*
  • L
CVE-2026-46745

*
  • H
Incorrect Authorization

*
  • H
Incorrect Authorization

*
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • L
Incomplete Blacklist

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Incomplete Blacklist

*
  • L
GHSA-6v7p-g79w-8964

*
  • L
Directory Traversal

*
  • L
Authentication Bypass

*
  • L
Improper Verification of Cryptographic Signature

*
  • L
GHSA-pw6j-qg29-8w7f

*
  • L
Resource Exhaustion

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Improper Validation of Specified Quantity in Input

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • L
GHSA-537c-gmf6-5ccf

*
  • L
Information Exposure

*
  • L
Improper Input Validation

*
  • L
Improper Initialization

*
  • L
Improper Resource Shutdown or Release

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Information Exposure

*
  • L
Resource Exhaustion

*
  • L
CRLF Injection

*
  • L
Unintended Proxy or Intermediary ('Confused Deputy')

*
  • L
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • L
Improper Validation of Certificate with Host Mismatch

*
  • L
Improper Authentication

*
  • L
Improper Cleanup on Thrown Exception

*
  • L
Interpretation Conflict

*
  • L
Buffer Over-read

*
  • L
Open Redirect

*
  • L
Incorrect Authorization

*
  • L
Use After Free

<2.11.2-r0
  • L
File and Directory Information Exposure

*
  • H
Deserialization of Untrusted Data

*
  • H
Origin Validation Error

*
  • L
CVE-2026-8838

*
  • H
Directory Traversal

*
  • L
Improper Certificate Validation

*
  • M
Inefficient Regular Expression Complexity

*
  • L
Information Exposure Through Log Files

*
  • L
Open Redirect

*
  • M
Information Exposure

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • L
Unprotected Alternate Channel

*
  • L
Use of a Broken or Risky Cryptographic Algorithm

*
  • L
Open Redirect

<2.11.2-r0
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Directory Traversal

*
  • L
Insufficient Granularity of Access Control

*
  • L
Insufficient Granularity of Access Control

*
  • L
CVE-2026-6357

*
  • M
HTTP Response Splitting

*
  • H
Information Exposure

*
  • H
Incorrect Authorization

*
  • M
Improper Certificate Validation

*
  • L
Information Exposure Through Log Files

*
  • M
Insecure Temporary File

*
  • L
GHSA-v4p8-mg3p-g94g

*
  • M
Improper Validation of Certificate with Host Mismatch

*
  • C
Out-of-Bounds

*
  • L
Uncontrolled Recursion

*
  • L
Resource Exhaustion

*
  • H
Directory Traversal

*
  • L
GHSA-r75f-5x8p-qvmc

*
  • L
Cross-site Request Forgery (CSRF)

*
  • L
CVE-2026-3219

*
  • M
HTTP Response Splitting

*
  • L
Resource Exhaustion

*
  • H
Improper Output Neutralization for Logs

*
  • L
Arbitrary Code Injection

*
  • M
Improper Input Validation

*
  • H
Arbitrary Code Injection

*
  • H
Improper Encoding or Escaping of Output

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Improper Input Validation

*
  • L
GHSA-69x8-hrgq-fjj8

*
  • M
Information Exposure

*
  • L
GHSA-xqmj-j6mv-4862

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
HTTP Response Splitting

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • H
Directory Traversal

*
  • L
Resource Exhaustion

*
  • L
CVE-2026-25219

*
  • L
Improper Authentication

*
  • L
Link Following

<2.11.2-r0
  • L
XML External Entity (XXE) Injection

*
  • M
Failure to Sanitize Special Element

<2.11.2-r0
  • L
Improper Verification of Cryptographic Signature

<2.11.2-r0
  • H
Improper Validation of Integrity Check Value

<2.11.2-r0
  • M
Not Failing Securely ('Failing Open')

<2.11.2-r0
  • M
Information Exposure

<2.11.2-r0
  • C
Buffer Overflow

<2.11.2-r0
  • L
Information Exposure

<2.11.2-r0
  • L
Arbitrary Code Injection

<2.11.2-r0
  • L
GHSA-72hv-8253-57qq

*
  • L
Origin Validation Error

<2.11.2-r0
  • C
Improper Verification of Cryptographic Signature

<2.11.2-r0
  • L
Insufficient Verification of Data Authenticity

<2.11.2-r0
  • L
GHSA-78cv-mqj4-43f7

<2.11.2-r0
  • L
Improper Control of Dynamically-Managed Code Resources

<2.11.2-r0
  • H
Resource Exhaustion

<2.11.2-r0
  • L
Information Exposure Through Log Files

<2.11.2-r0
  • L
CVE-2026-2473

<2.11.2-r0
  • L
CVE-2026-2472

<2.11.2-r0
  • M
Information Exposure Through Caching

*
  • M
Declaration of Catch for Generic Exception

<2.11.2-r0
  • L
GHSA-27jp-wm6q-gp25

<2.11.2-r0
  • M
Improper Handling of Windows Device Names

<2.11.2-r0
  • L
Information Exposure

*
  • M
CVE-2026-26007

<2.11.2-r0
  • L
CVE-2026-1703

*
  • H
CVE-2026-0994

<2.11.2-r0
  • M
Directory Traversal

*
  • M
Allocation of Resources Without Limits or Throttling

<2.11.2-r0
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<2.11.2-r0
  • H
Allocation of Resources Without Limits or Throttling

<2.11.2-r0
  • H
Cross-site Request Forgery (CSRF)

<2.11.2-r0
  • M
Logging of Excessive Data

<2.11.2-r0
  • M
HTTP Request Smuggling

<2.11.2-r0
  • L
Incomplete Blacklist

<2.11.2-r0
  • L
Allocation of Resources Without Limits or Throttling

<2.11.2-r0
  • L
Link Following

<2.11.2-r0
  • M
HTTP Request Smuggling

<2.11.2-r0
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<2.11.2-r0
  • L
Improper Handling of Highly Compressed Data (Data Amplification)

<2.11.2-r0
  • M
Directory Traversal

<2.11.2-r0
  • L
Information Exposure Through Log Files

<2.11.2-r0
  • H
Deserialization of Untrusted Data

<2.11.2-r0
  • L
Link Following

<2.11.2-r0
  • M
Improper Certificate Validation

<2.11.2-r0
  • L
Asymmetric Resource Consumption (Amplification)

<2.11.2-r0
  • M
Link Following

<2.11.2-r0
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<2.11.2-r0
  • H
Allocation of Resources Without Limits or Throttling

<2.11.2-r0
  • M
Improper Handling of Windows Device Names

<2.11.2-r0
  • L
Insecure Default Initialization of Resource

<2.11.2-r0
  • L
Arbitrary Code Injection

<2.11.2-r0
  • M
Open Redirect

<2.11.2-r0
  • M
Open Redirect

<2.11.2-r0
  • H
Out-of-bounds Write

<2.11.2-r0
  • M
Directory Traversal

<2.11.2-r0
  • L
CVE-2025-8869

*
  • L
Improper Authentication

*
  • M
Open Redirect

*
  • L
CVE-2024-34069

<2.11.2-r0
  • H
Resource Exhaustion

<2.11.2-r0