Skip to content

Apache Superset security advisories

66 advisories · 2 critical or high in 12 months · latest Feb 24

60 of 66 advisories

DateAdvisory
Feb 24Apache Superset Improper Authorization allows low-privileged users to bypass access controls
CVE-2026-23982Highfixed in 6.0.0
Feb 24Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
CVE-2026-23969Mediumfixed in 4.1.2
Feb 24Apache Superset allows privileged users to conduct error-based SQL Injection
CVE-2026-23980Mediumfixed in 6.0.0
Feb 24Apache Superset allows authenticated users to view sensitive data without explicit permissions
CVE-2026-23983Lowfixed in 6.0.0
Feb 24Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
CVE-2026-23984Highfixed in 6.0.0
Aug 142025Apache Superset data query improperly discloses database schema information to low-privileged guest user
CVE-2025-55673Mediumfixed in 4.1.3.post1
Aug 142025Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
CVE-2025-55672Mediumfixed in 5.0.0
Aug 142025Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
CVE-2025-55674Mediumfixed in 5.0.0
Aug 142025Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
CVE-2025-55675Mediumfixed in 5.0.0
May 302025Apache Superset: Improper authorization bypass on row level security via SQL Injection
CVE-2025-48912Highfixed in 4.1.2
May 132025Apache Superset Allows Ownership Takeover
CVE-2025-27696Medium8.8fixed in 4.1.2
Dec 122024Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
CVE-2024-55633High6.5fixed in 4.1.0
Dec 92024Apache Superset: Error verbosity exposes metadata in analytics databases
CVE-2024-53948Medium5.3fixed in 4.1.0
Dec 92024Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled
CVE-2024-53949High6.5fixed in 4.1.0
Dec 92024Apache Superset: Improper SQL authorisation, parse not checking for specific postgres functions
CVE-2024-53947Low9.8fixed in 4.1.0
Jul 162024Apache Superset vulnerable to improper SQL authorization
CVE-2024-39887Medium4.3fixed in 4.0.2
Jun 202024Apache Superset server arbitrary file read
CVE-2024-34693Medium6.8fixed in 3.1.3, 4.0.1
May 72024Apache Superset Incorrect Authorization vulnerability
CVE-2024-28148Medium4.3fixed in 3.1.2
Feb 282024Apache Superset: Improper authorization validation on dashboards and charts import
CVE-2024-26016Medium4.3fixed in 3.0.4, 3.1.1
Feb 282024Apache Superset: Improper data authorization when creating a new dataset
CVE-2024-24779Medium5.0fixed in 3.0.4, 3.1.1
Feb 282024Apache Superset: Improper validation of SQL statements allows for unauthorized access to data
CVE-2024-24773Medium4.9fixed in 3.0.4, 3.1.1
Feb 282024Apache Superset: Improper Neutralization of custom SQL on embedded context
CVE-2024-24772Medium4.3fixed in 3.0.4, 3.1.1
Feb 282024Apache Superset: Improper error handling on alerts
CVE-2024-27315Medium4.3fixed in 3.0.4, 3.1.1
Jan 232024Cross-site Scripting in Apache superset
CVE-2023-49657Critical9.6fixed in 3.0.3
Dec 192023Apache Superset uncontrolled resource consumption
CVE-2023-46104Medium6.5fixed in 2.1.2, 3.1.0rc1
Dec 192023Apache Superset incorrect write permissions vulnerability
CVE-2023-49734High7.7fixed in 2.1.3, 3.0.2
Dec 192023Apache Superset SQL injection vulnerability
CVE-2023-49736Medium6.5fixed in 2.1.3, 3.0.2
Nov 282023Apache Superset - Elevation of Privilege
CVE-2023-40610High7.3fixed in 2.1.2
Nov 282023Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
CVE-2023-42504Medium6.5fixed in 3.0.0
Nov 282023Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
CVE-2023-42505Medium4.3fixed in 3.0.0
Nov 282023Apache Superset Open Redirect vulnerability
CVE-2023-42502Medium5.4fixed in 3.0.0
Nov 272023Apache Superset has Incorrect Default Permissions
CVE-2023-42501Medium4.3fixed in 2.1.2
Nov 272023Apache Superset Cross-site Scripting vulnerability
CVE-2023-43701Medium4.3fixed in 2.1.2
Sep 62023Apache Superset has incorrect authorization check
CVE-2023-32672Medium4.3no fix yet
Sep 62023Apache Superset Deserialization of Untrusted Data vulnerability
CVE-2023-37941Medium6.6fixed in 2.1.1
Sep 62023Apache Superset Improper Input Validation vulnerability
CVE-2023-39265Medium6.5no fix yet
Sep 62023Apache Superset Server Side Request Forgery vulnerability
CVE-2023-36388Medium4.3no fix yet
Sep 62023Apache Superset has improper default REST API permission for Gamma users
CVE-2023-36387Medium5.4no fix yet
Sep 62023Apache Superset users may incorrectly create resources using the import charts feature
CVE-2023-27526Medium4.3no fix yet
Sep 62023Apache Superset may expose internal traces on REST API endpoints
CVE-2023-39264Medium4.3no fix yet
Sep 62023Apache Superset vulnerable to improper data authorization
CVE-2023-27523Medium5.0no fix yet
Jul 62023Apache Superset vulnerable to Exposure of Sensitive Information
CVE-2023-30776Medium6.5fixed in 2.1.0
Jul 62023Apache Superset Server-Side Request Forgery vulnerability
CVE-2023-25504Medium6.5fixed in 2.1.0
Apr 242023Apache superset missing check for default SECRET_KEY
CVE-2023-27524High8.9fixed in 2.1.0
Apr 172023Apache Superset vulnerable to Improper Authorization
CVE-2023-27525Medium4.3no fix yet
Jan 162023Apache Superset vulnerable to Cross-Site Request Forgery via legacy REST API endpoints
CVE-2022-43719High8.8no fix yet
Jan 162023Apache Superset is vulnerable to Cross-Site Scripting (XSS)
CVE-2022-43718Medium5.4no fix yet
Jan 162023Apache Superset vulnerable to Cross-site Scripting
CVE-2022-43717Medium5.4no fix yet
Jan 162023Apache Superset's SQL Alchemy connector vulnerable to SQL Injection
CVE-2022-41703Medium5.4no fix yet
Jan 162023Apache Superset has Improper Access Control
CVE-2022-45438Medium5.3no fix yet
Jan 162023Apache Superset Open Redirect vulnerability
CVE-2022-43721Medium5.4no fix yet
Jan 162023Apache Superset vulnerable to Injection
CVE-2022-43720Medium5.4no fix yet
Jul 72022Apache Superset allows authenticated users to access metadata they have no permission to
CVE-2021-37839Medium4.3fixed in 1.5.1
May 242022Apache Superset Stored XSS on Dashboard markdown
CVE-2021-27907Medium5.4fixed in 0.38.1
May 242022Apache Superset OS Command Injection
CVE-2020-13948High8.8fixed in 0.37.1
May 242022Improper Encoding or Escaping of Output in Apache Superset
CVE-2021-42250High6.5fixed in 1.3.2
May 242022Apache Superset allowed for database connections password leak for authenticated users
CVE-2021-41972High6.5fixed in 1.3.2
May 242022Apache Superset Cross-site Scripting (XSS) vulnerability on the Explore page
CVE-2021-32609Medium5.4fixed in 1.2.0
May 242022Apache Superset SQL Injection when template processing is enabled
CVE-2021-41971High8.8fixed in 1.3.1
Apr 142022SQL injection in apache-superset
CVE-2022-27479Critical9.8fixed in 1.4.2
About Apache Superset

Open-source BI and dashboards.

Packages watched: apache-superset (PyPI).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.