Apache Airflow Flaws Enable Security Bypass and Multiple Additional Vulnerabilities
German authorities issued advisories for Apache Airflow covering a vulnerability that can bypass security measures and a separate notice for multiple vulnerabilities affecting the workflow orchestration platform. The alerts indicate that Airflow deployments may be exposed to weaknesses that undermine intended protections and introduce additional security risk across affected environments.
Organizations using Apache Airflow should review the referenced advisories, identify affected versions, and prioritize vendor-recommended updates or mitigations. Because Airflow is commonly used to manage automated data pipelines and scheduled jobs, successful exploitation could weaken access controls or expose connected systems and workflows to further compromise.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
9 events from the most recent confirmed update back to the earliest known activity.
dCERT publishes Airflow OpenSearch/Elasticsearch Providers advisory 2026-1423
dCERT published advisory 2026-1423 covering multiple vulnerabilities in Apache Airflow Providers OpenSearch and Elasticsearch that could allow information disclosure. This is a new advisory separate from earlier Apache Airflow disclosures in the timeline.
dCERT publishes Apache Airflow multiple vulnerabilities advisory 2026-1254
dCERT published advisory 2026-1254 for Apache Airflow, disclosing multiple vulnerabilities that could allow information disclosure. This is a new advisory separate from the previously listed Apache Airflow disclosures.
dCERT publishes Apache Airflow and Keycloak Provider advisory 2026-1146
dCERT published advisory 2026-1146 covering multiple vulnerabilities affecting Apache Airflow and the Apache Airflow Keycloak Provider. This is a new advisory separate from the previously listed Apache Airflow disclosures.
dCERT publishes Apache Airflow information disclosure advisory 2026-1137
dCERT published advisory 2026-1137 for Apache Airflow, disclosing a vulnerability that could allow information disclosure. This is a new advisory separate from the previously listed Apache Airflow disclosures.
dCERT publishes Apache Airflow information disclosure advisory 2026-1126
dCERT published advisory 2026-1126 for Apache Airflow, disclosing a vulnerability that could allow information disclosure. This is a new advisory separate from earlier Apache Airflow vulnerability disclosures.
dCERT publishes Apache Airflow code execution advisory 2026-1101
dCERT published advisory 2026-1101 for Apache Airflow, disclosing a vulnerability that could allow code execution. This is a new advisory separate from the previously listed Apache Airflow disclosures.
dCERT publishes Apache Airflow multiple vulnerabilities advisory 2026-1052
dCERT published advisory 2026-1052 for Apache Airflow, disclosing multiple vulnerabilities affecting the platform. This represents a new advisory separate from earlier Apache Airflow disclosures.
dCERT publishes Apache Airflow multiple vulnerabilities advisory 2026-1021
dCERT published advisory 2026-1021 covering multiple vulnerabilities affecting Apache Airflow, indicating additional or broader security issues were disclosed.
dCERT publishes Apache Airflow security bypass advisory 2026-0896
dCERT published advisory 2026-0896 for Apache Airflow, stating that a vulnerability could allow bypassing security measures.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
9 references tracked. Mallory keeps watching after this page renders.
dCERT - Advisory 2026-1423 - Apache Airflow Providers OpenSearch and Elasticsearch: Multiple Vulnerabilities allow information disclosure
dcert.de
Open sourcedCERT - Advisory 2026-1254 - Apache Airflow: Multiple Vulnerabilities allow information disclosure
dcert.de
Open sourcedCERT - Advisory 2026-1146 - Apache Airflow and Apache Airflow Keycloak Provider: Multiple Vulnerabilities
dcert.de
Open sourcedCERT - Advisory 2026-1137 - Apache Airflow: Vulnerability allows information disclosure
dcert.de
Open sourcedCERT - Advisory 2026-1126 - Apache Airflow: Vulnerability allows information disclosure
dcert.de
Open sourcedCERT - Advisory 2026-1101 - Apache Airflow: Vulnerability allows code execution
dcert.de
Open sourcedCERT - Advisory 2026-1052 - Apache Airflow: Multiple Vulnerabilities
dcert.de
Open sourcedCERT - Advisory 2026-1021 - Apache Airflow: Multiple Vulnerabilities
dcert.de
Open sourcedCERT - Advisory 2026-0896 - Apache Airflow: Vulnerability allows bypassing security measures
dcert.de
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


