Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. apache-airflow
  4. ›
  5. CVE-2026-45426

CVE-2026-45426: Apache Airflow has an Incorrect Authorization issue

June 1, 2026 (updated July 9, 2026)

Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow’s Log server authorized JWT tokens against Dag IDs by applying Python’s str.lstrip() to the requested path segment when verifying the JWT’s sub claim. str.lstrip() strips any of a set of characters from the left (not a prefix), so a JWT issued for a Dag named e.g. dag_a would authorize log access to any other Dag whose name began with any subset of the characters {d, a, g, _} (e.g. dag_attacker, aaaa_target, _dag_secret). Such an authenticated worker could enumerate and read worker logs of other Dags whose names happened to share that character-class prefix, leaking task output and error traces beyond the documented per-Dag isolation boundary. Affects deployments relying on per-Dag log-access scoping (multi-team, shared-executor, shared-worker topologies). Users are advised to upgrade to apache-airflow 3.2.2 or later.

References

  • github.com/advisories/GHSA-x5wm-j6wh-2834
  • github.com/apache/airflow/pull/66749
  • github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2026-174.yaml
  • lists.apache.org/thread/hz1q7vg65vq2h4fobv5ww8tp257fbqj9
  • nvd.nist.gov/vuln/detail/CVE-2026-45426

Code Behaviors & Features

Detect and mitigate CVE-2026-45426 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.0.0 before 3.2.2

Fixed versions

  • 3.2.2

Solution

Upgrade to version 3.2.2 or above.

Impact 3.1 LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-863: Incorrect Authorization

Source file

pypi/apache-airflow/CVE-2026-45426.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:19:09 +0000.