<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:21:47 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-28563 — Apache Airflow: DAG authorization bypass</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-28563</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache Airflow&lt;/p&gt;
&lt;p&gt;Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission to enumerate DAGs they are not authorized to view.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Apache Software Foundation Apache Airflow&lt;/p&gt;
&lt;p&gt;Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission to enumerate DAGs they are not authorized to view.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-28563</guid>
    </item>
    <item>
      <title>GHSA-x3fv-96qh-67m7 — Apache Airflow: DAG authorization bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x3fv-96qh-67m7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: apache-airflow&lt;/p&gt;
&lt;p&gt;Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission to enumerate DAGs they are not authorized to view.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: apache-airflow&lt;/p&gt;
&lt;p&gt;Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filtering by authorized DAG IDs. This allows an authenticated user with only DAG Dependencies permission to enumerate DAGs they are not authorized to view.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x3fv-96qh-67m7</guid>
    </item>
  </channel>
</rss>
