Skip to content
Apache AirflowGHSA-j482-47xf-p25c

Apache Airflow Potential Cross-site Scripting Vulnerability

Medium5.4CVE-2024-39863 · Published Jul 17, 2024 · updated Sep 10, 2026

Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended to upgrade to version 2.9.3, which fixes this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.9.32.9.3
Details and references

More Apache Airflow advisories

All Apache Airflow

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.