Skip to content
Threat Feed
medium advisory

Multiple Vulnerabilities in Apache Airflow Providers

Apache Airflow is affected by multiple vulnerabilities, specifically CVE-2024-48792 and CVE-2024-48793, which allow a remote, authenticated attacker to perform unauthorized information disclosure.

CVE search metadata

CVE search record: CVE-2024-48792. Severity: high. CVSS: 7.5. EPSS: 0.49%. KEV: no. Product: Airflow. Brief: Multiple Vulnerabilities in Apache Airflow Providers. Brief link: https://feed.craftedsignal.io/briefs/2026-08-apache-airflow-vulnerabilities/

CVE search record: CVE-2024-48793. Severity: medium. CVSS: 5.9. EPSS: 0.30%. KEV: no. Product: Airflow. Brief: Multiple Vulnerabilities in Apache Airflow Providers. Brief link: https://feed.craftedsignal.io/briefs/2026-08-apache-airflow-vulnerabilities/

Apache Airflow has been identified as vulnerable to multiple security issues, specifically tracked as CVE-2024-48792 and CVE-2024-48793. These vulnerabilities allow a remote, authenticated attacker to successfully execute unauthorized information disclosure within an Airflow environment. The vulnerabilities reside within the Airflow provider packages, which are commonly utilized for integrating Airflow with various cloud and third-party services. Defenders should prioritize auditing access logs and user permission configurations for Airflow instances, ensuring that the principle of least privilege is applied to authenticated users to mitigate the impact of potential exploitation attempts. Organizations should review their current version of Apache Airflow and any installed provider packages to ensure they are updated to the latest available versions released by the project to remediate these specific information disclosure flaws.

Impact

Successful exploitation of these vulnerabilities results in unauthorized information disclosure, potentially exposing sensitive workflow data, configuration details, or connection credentials stored within the Airflow instance. This could lead to further reconnaissance or lateral movement by an attacker who has already obtained initial authentication.

Recommendation

  • Upgrade Apache Airflow and all relevant provider packages to the latest versions released by the Apache Software Foundation to remediate CVE-2024-48792 and CVE-2024-48793.
  • Review and tighten access control lists for all authenticated users to limit exposure to sensitive data.
  • Monitor logs for unusual or unauthorized access patterns targeting the Airflow web interface or API endpoints.

Immediate actions

Audit Apache Airflow provider versions

IT Operations 48h

Mitigations

Upgrade Apache Airflow to patched versions

immediate IT Operations

CVE-2024-48792, CVE-2024-48793