PT-2026-25892 · Apache · Apache Airflow

·

CVE-2026-28563

·

Publicado

2026-03-17

·

Atualizado

2026-07-12

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions 3.1.0 through 3.1.7
Description The /ui/dependencies endpoint in Apache Airflow returns the complete DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission to enumerate DAGs they are not authorized to view.
Recommendations Upgrade to Apache Airflow version 3.1.8 or later.

Exploit

Correção

DoS

Incorrect Permission

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05614
BIT-AIRFLOW-2026-28563
BIT-AIRFLOW-2026-48891
CVE-2026-28563
ECHO-9AC2-76F0-F382
GHSA-3322-MJXH-9MP5
GHSA-X3FV-96QH-67M7
PYSEC-2026-15
PYSEC-2026-2086

Produtos afetados

Apache Airflow