Skip to content
Apache AirflowGHSA-hhx9-p69v-cx2j

Authentication bypass in Apache Airflow

Critical9.8CVE-2020-13927 · Published Apr 30, 2021 · updated Oct 22, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 1.10.111.10.11
Details and references

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at https://airflow.apache.org/docs/1.10.11/security.html#api-authentication. Note this change fixes it for new installs but existing users need to change their config to default `[api]auth_backend = airflow.api.auth.backend.deny_all` as mentioned in the Updating Guide: https://github.com/apache/airflow/blob/1.10.11/UPDATING.md#experimental-api-will-deny-all-request-by-default

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-1056, CWE-1188, CWE-287, CWE-306
Also known as
BIT-airflow-2020-13927, CVE-2020-13927, PYSEC-2020-18

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Apr 202021Incorrect Session Validation in Apache Airflow
CVE-2020-17526High7.7fixed in 1.10.14
Apr 202021Apache Airflow cross-site scripting due to incomplete fix for CVE-2020-13944
CVE-2020-17515Medium6.1fixed in 1.10.15rc1, 2.0.2rc1
Apr 72021Improper Access Control in Apache Airflow
CVE-2021-26559High6.5fixed in 2.0.1rc1
Jun 182021Apache Airflow Cross-site Scripting
CVE-2020-13944Medium6.1fixed in 1.10.12
Jun 182021Improper Authentication in Apache Airflow
CVE-2021-26697Medium5.3fixed in 2.0.1rc1
Jun 182021Cross-site Scripting in Apache Airflow
CVE-2021-28359Medium6.1fixed in 1.10.15, 2.0.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.