← All credits
Jarek Potiuk
57 vulnerability records and advisories credit this contributor.
CVE-2026-81914
Apache Airflow Google provider: Google Drive query injection via unescaped file and folder names
CVE-2026-81862
Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credentials in SQL text, task logs and Teradata query logs
CVE-2026-86843
Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-cluster example Dag
CVE-2026-81930
Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain
CVE-2026-82355
Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation
CVE-2026-75158
Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter
CVE-2026-86473
Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry
CVE-2026-75157
Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression)
CVE-2026-86466
Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated
CVE-2026-86462
Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions