Authorization Flaw in Apache Airflow Affects Multiple Versions
CVE-2026-26929
6.5MEDIUM
What is CVE-2026-26929?
The FastAPI DagVersion listing API in Apache Airflow versions 3.0.0 through 3.1.7 does not implement proper per-DAG authorization filtering when requests are made with a wildcard dag_id ('~'). This allows unauthorized users to access metadata for DAGs that they are not permitted to view, exposing sensitive information. It is crucial for users to upgrade to Apache Airflow version 3.1.8 or later to mitigate this vulnerability.
Affected Version(s)
Apache Airflow 3.0.0 < 3.1.8