Authorization Bypass Through User-Controlled Key Affecting apache-airflow-core package, versions [,3.3.0b1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Social Trends
EPSS
0.4% (33rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWCORE-17879170
  • published7 Jul 2026
  • disclosed7 Jul 2026
  • creditMatteo Panzeri, Jarek Potiuk

Introduced: 7 Jul 2026

CVE-2026-49296  (opens in a new tab)
CWE-639  (opens in a new tab)

How to fix?

Upgrade apache-airflow-core to version 3.3.0b1 or higher.

Overview

Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the GET /api/v2/dagSources/{dag_id} endpoint, which returns the entire source file containing multiple DAGs without redacting those the user is not authorized to access. An attacker can obtain unauthorized access to the source code of other DAGs by making a request to this endpoint. This is only exploitable if multiple DAGs are defined in a single file and per-DAG access control is relied upon to restrict source visibility.

CVSS Base Scores

version 4.0
version 3.1