oss-sec mailing list archives

CVE-2026-40963: Apache Airflow: DAG authorization bypass on /ui/structure/structure_data


From: Rahul Vats <rahulvats () apache org>
Date: Sun, 31 May 2026 11:39:07 +0000

Severity: low 

Affected versions:

- Apache Airflow (apache-airflow) 3.0.0 before 3.2.2

Description:

The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking 
whether the caller had read permission on those linked Dags. An authenticated UI/API user authorized for one Dag could 
enumerate linked Dag IDs and dependency metadata for other Dags they were not authorized to read. Affects deployments 
that rely on per-Dag read scoping to keep Dag dependency topology private across teams. Users are advised to upgrade to 
`apache-airflow` 3.2.2 or later.

Credit:

Masamune - Unit515 OPSWAT (finder)
Jarek Potiuk (remediation developer)

References:

https://github.com/apache/airflow/pull/65342
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-40963


Current thread: