Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <60a59fa4-ed6b-7e3b-0df6-e39f953f9f0c@apache.org>
Date: Mon, 09 Feb 2026 09:48:01 +0000
From: Ephraim Anierobi <ephraimanierobi@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2026-22922: Apache Airflow: Airflow externalLogUrl Permission
 Bypass 

Severity: low 

Affected versions:

- Apache Airflow (apache-airflow) 3.1.0 before 3.1.7

Description:

Apache Airflow versions 3.1.0 through 3.1.6 contain an authorization flaw that can allow an authenticated user with custom permissions limited to task access to view task logs without having task log access. 

Users are recommended to upgrade to Apache Airflow 3.1.7 or later, which resolves this issue.

Credit:

34selen (finder)
Shubham Raj (remediation developer)

References:

https://github.com/apache/airflow/pull/60412
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-22922

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.