Apache Airflow 3.3.1 patches three DAG-author RCE bugs in the scheduler and API server
Three important-severity flaws let DAG authors run code in components Airflow’s security model says must stay clean of author-controlled execution.
By tarpitThree important-severity flaws let DAG authors run code in components Airflow’s security model says must stay clean of author-controlled execution.
By tarpitCVE-2026-59113 let a crafted page drive OS protocol handlers and premature extension URL overrides when users fetched untrusted content.
By renderUnauthenticated attackers can leak server secrets, and potentially escalate to RCE, on apps using libvips with untrusted uploads.
By nonceA single DNS-over-QUIC connection could overflow a heap buffer; the flaw is fixed in 6.4.1.
By tarpit