Apache AirflowGHSA-8x34-9q3v-h7g8
Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization
High8.1CVE-2026-30911 · Published Mar 17, 2026 · updated Jun 5, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | >= 3.1.0, < 3.1.8 | 3.1.8 |
Details and references
Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instance. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-862
- Also known as
- BIT-airflow-2026-30911, CVE-2026-30911, PYSEC-2026-17
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 17 | Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata CVE-2026-26929High7.5fixed in 3.1.8 | High7.5 | 3.1.8 |
| Mar 17 | Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications CVE-2026-28779High7.5fixed in 3.1.8 | High7.5 | 3.1.8 |
| Mar 17 | Apache Airflow: DAG authorization bypass CVE-2026-28563Medium4.3fixed in 3.1.8 | Medium4.3 | 3.1.8 |
| Mar 31 | Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange CVE-2026-32794Medium4.8fixed in 1.12.0 | Medium4.8 | 1.12.0 |
| Feb 24 | Apache Airflow exposes sensitive information in its log files CVE-2025-27555Medium6.5fixed in 2.11.1 | Medium6.5 | 2.11.1 |
| Feb 24 | Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table CVE-2024-56373High8.4fixed in 2.11.1 | High8.4 | 2.11.1 |