Information Disclosure Vulnerability in Apache Airflow by Apache
CVE-2026-28563
4.3MEDIUM
What is CVE-2026-28563?
An information disclosure vulnerability exists in Apache Airflow versions from 3.1.0 to 3.1.7. The /ui/dependencies endpoint exposes the full Directed Acyclic Graph (DAG) dependency information without properly filtering by the authorized DAG IDs. This flaw allows authenticated users who possess only DAG Dependencies permissions to enumerate and access DAGs that they should not have visibility into. To mitigate this risk, it is advised to upgrade to Apache Airflow version 3.1.8 or later, which addresses this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Airflow 3.0.0 < 3.1.8
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Masamune - Unit515 OPSWAT
Shubham Raj