Missing Authorization Affecting apache-airflow-core package, versions [3.0.0rc1,3.2.0rc1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.69% (48th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWCORE-15954288
  • published9 Apr 2026
  • disclosed9 Apr 2026
  • creditselen

Introduced: 9 Apr 2026

CVE-2026-34538  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade apache-airflow-core to version 3.2.0rc1 or higher.

Overview

Affected versions of this package are vulnerable to Missing Authorization through the wait_dag_run_until_finished handler in airflow-core/src/airflow/api_fastapi/core_api/routes/public/dag_run.py. An attacker can read task result values by sending a GET request to the DAG run wait endpoint with the result query parameter while holding only DAG run read access, such as the Viewer role. This exposes XCom payloads that are intended to remain protected, allowing sensitive execution results to be returned to users who should only be able to inspect DAG and run state.

CVSS Base Scores

version 4.0
version 3.1