CVE-2026-26929

Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filtering when the request is made with dag_id set to "~" (wildcard for all DAGs). As a result, version metadata of DAGs that the requester is not authorized to access is returned. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

History

17 Mar 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 6.5

17 Mar 2026, 15:50

Type Values Removed Values Added
References () https://github.com/apache/airflow/pull/61675 - () https://github.com/apache/airflow/pull/61675 - Issue Tracking
References () https://lists.apache.org/thread/g5o6khx83jwqvdyn0mlyb0krt35cs9ss - () https://lists.apache.org/thread/g5o6khx83jwqvdyn0mlyb0krt35cs9ss - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2026/03/17/4 - () http://www.openwall.com/lists/oss-security/2026/03/17/4 - Mailing List, Third Party Advisory
First Time Apache airflow
Apache
CPE cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

17 Mar 2026, 14:20

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/03/17/4 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

17 Mar 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 11:16

Updated : 2026-03-17 16:16


NVD link : CVE-2026-26929

Mitre link : CVE-2026-26929

CVE.ORG link : CVE-2026-26929


JSON object : View

Products Affected

apache

  • airflow
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource