Skip to content
Apache AirflowGHSA-w7rc-q6cm-f5gm

Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions

Medium4.3CVE-2026-40690 · Published Apr 24, 2026 · updated Jul 13, 2026

The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at least one DAG could browse the asset graph for any other asset in the deployment and learn the existence and names of DAGs and assets outside their authorized scope. Users are recommended to upgrade to version 3.2.1, which fixes this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 3.2.1rc13.2.1rc1
Details and references

More Apache Airflow advisories

All Apache Airflow
Advisory
Apache Airflow: improper access control
Medium4.3Apr 24
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
Low3.7Apr 18
In case of SQL errors
High7.5Apr 18
Apache Airflow: code execution
High7.2Apr 18
Apache Airflow: JWT token appearing in logs
Medium7.5Apr 16
Apache Airflow: RCE by race condition in example_xcom dag
High8.1Apr 16

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.