Skip to content
Apache AirflowGHSA-x2x7-p37c-43cr

Apache Airflow has a Missing Authorization issue

Medium4.3CVE-2026-41014 · Published Jun 1, 2026 · updated Jul 9, 2026

The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerate partition run state, schedule configuration, and asset wiring for Dags they were not authorized to read. Affects deployments that rely on per-Dag read scoping while granting users broader Asset access. Users are advised to upgrade to `apache-airflow` 3.2.2 or later.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
>= 3.2.0, < 3.2.23.2.2
Details and references

More Apache Airflow advisories

All Apache Airflow

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.