Skip to content
Apache AirflowGHSA-9xpj-62mm-24h2

Apache Airflow does not return the "Cache-Control" header for dynamic content

LowCVE-2024-25142 · Published Jun 14, 2024 · updated Sep 10, 2026

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This issue affects Apache Airflow: before 2.9.2. Users are recommended to upgrade to version 2.9.2, which fixes the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.9.22.9.2
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow Cross-site Scripting Vulnerability
Medium6.1Aug 21, 2024
Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB
Critical9.8Aug 5, 2024
Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
High8.8Jul 17, 2024
Apache Airflow Potential Cross-site Scripting Vulnerability
Medium5.4Jul 17, 2024
Apache Airflow: XSS vulnerability in Task Instance Log/Log Details
Medium5.4May 14, 2024
Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
Medium4.3Apr 18, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.