Programmatically author, schedule and monitor data pipelines
apache-airflow has critical vulnerabilities — do not use
Update to >= 4.0.0 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| critical | BIT-airflow-2023-22884 | Command Injection in Apache Airflow and Apache Airflow MySQL Provider | 4.0.0 |
| high | BIT-airflow-2024-45498 | Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an authenticated attacker with only DAG trigger permission to execute arbitrary commands. If you used that example as the base of your DAGs - please review if you have not copied the dangerous example; see https://github.com/apache/airflow/pull/41873 for more information. We recommend against exposing the example DAGs in your deployment. If you must expose the example DAGs, upgr | — |
| medium | BIT-airflow-2025-54831 | Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access to sensitive connection fields to Connection Editing Users, effectively applying a "write-only" model for sensitive values. In Airflow 3.0.3, this model was unintentionally violated: sensitive connection information could be viewed by users with READ permissions through both the API and the UI. This behavior also bypassed the `AIRFLOW__CORE__HIDE_SENSITIVE_VAR_CONN_FI | — |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/pypi/apache-airflowLast updated · 2026-07-06T13:55:35.022929Z