Home

Description

Apache Airflow versions before 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later, which resolves this issue

PUBLISHED Reserved 2026-01-21 | Published 2026-02-09 | Updated 2026-02-09 | Assigner apache

Problem types

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Product status

Default status
unaffected

Any version before 3.1.7
affected

Credits

Saurabh finder

References

www.openwall.com/lists/oss-security/2026/02/09/3

github.com/apache/airflow/pull/60801 patch

lists.apache.org/thread/nx96435v77xdst7ls5lk57kqvqyj095x vendor-advisory

cve.org (CVE-2026-24098)

nvd.nist.gov (CVE-2026-24098)

Download JSON