Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2017-17836 Apache Airflow vulnerable to XSSCVE-2020-11981 Command injection via Celery broker in Apache AirflowCVE-2020-11982 Insecure default config of Celery worker in Apache AirflowCVE-2020-13927 Authentication bypass in Apache AirflowCVE-2022-38649 OS Command Injection in Apache AirflowCVE-2022-40189 OS Command Injection in Apache AirflowCVE-2023-22884 Command Injection in Apache Airflow and Apache Airflow MySQL ProviderCVE-2023-25754 Apache Airflow vulnerable to Privilege Context Switching ErrorCVE-2022-24439 GitPython: improper user input validation leads into a RCECVE-2023-40267 GitPython: Insecure non-multi options in clone and clone_from is not blockedCVE-2019-6446 numpy: crafted serialized object passed in numpy.load() in pickle python module allows arbitrary code executionCVE-2017-18342 PyYAML: yaml.load() API could execute arbitrary codeCVE-2020-14343 PyYAML: incomplete fix for CVE-2020-1747CVE-2019-7164 python-sqlalchemy: SQL Injection when the order_by parameter can be controlledCVE-2019-7548 python-sqlalchemy: SQL Injection when the group_by parameter can be controlledCVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposureCVE-2017-15720 Improper Input Validation in Apache Airflow resulting in Remote Code ExecutionCVE-2017-17835 Cross-Site Request Forgery (CSRF) in Apache AirflowCVE-2018-20245 Improper Certificate Validation in Apache AirflowCVE-2019-0229 Apache Airflow vulnerable to CSRF AttacksCVE-2020-11978 Remote code execution (RCE) in Apache AirflowCVE-2020-17526 Incorrect Session Validation in Apache AirflowCVE-2022-24288 OS Command injection in Apache AirflowCVE-2022-27949 Apache Airflow subject to Exposure of Sensitive InformationCVE-2022-40127 Apache Airflow vulnerable to OS Command Injection via example DAGsYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2019-149 In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow, PYSEC-2020-15 An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resuPYSEC-2020-16 An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payPYSEC-2020-18 The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the dePYSEC-2023-314 Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider.
This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.
PYSEC-2023-59 Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.
PYSEC-2025-87 Edge3 Worker RPC RCE on Airflow 2.
This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2.
The Edge3 provider support in AirflowPYSEC-2026-2082 A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed aPYSEC-2026-267 OS Command Injection in Apache AirflowPYSEC-2026-268 Command Injection in Apache Airflow and Apache Airflow MySQL ProviderPYSEC-2026-270 OS Command Injection in Apache AirflowPYSEC-2022-42992 All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clonePYSEC-2023-137 GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.PYSEC-2026-2161 GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options))PYSEC-2019-108 ** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized objectPYSEC-2018-49 In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced foPYSEC-2021-142 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or PYSEC-2019-123 SQLAlchemy before 1.3.0b3 allows SQL Injection via the order_by parameter. The fix (commit 30307c4) was applied only to the main branch and was never backported to the 1.2.x release line; all 1.2.x vePYSEC-2019-124 SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.PYSEC-2018-32 urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentialPYSEC-2018-45 It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other broPYSEC-2019-142 In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.PYSEC-2019-143 The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checkinPYSEC-2019-147 In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.PYSEC-2019-148 In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.Code that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.