Information Disclosure Vulnerability in Apache Airflow by Apache
CVE-2026-28563
4.3MEDIUM
What is CVE-2026-28563?
An information disclosure vulnerability exists in Apache Airflow versions from 3.1.0 to 3.1.7. The /ui/dependencies endpoint exposes the full Directed Acyclic Graph (DAG) dependency information without properly filtering by the authorized DAG IDs. This flaw allows authenticated users who possess only DAG Dependencies permissions to enumerate and access DAGs that they should not have visibility into. To mitigate this risk, it is advised to upgrade to Apache Airflow version 3.1.8 or later, which addresses this issue.
Affected Version(s)
Apache Airflow 3.0.0 < 3.1.8