gitsafehub
github.com/hashnuke/hello-airflow ↗

hashnuke/hello-airflow

scanned 2026-08-15 · git 891d94f
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies181Known OSS vulnerabilities200Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 181 found · 16 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2017-17836 Apache Airflow vulnerable to XSS
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2017-17836). Fix: Update that package to its patched version.
  • Serious CVE-2020-11981 Command injection via Celery broker in Apache Airflow
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2020-11981). Fix: Update that package to its patched version.
  • Serious CVE-2020-11982 Insecure default config of Celery worker in Apache Airflow
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2020-11982). Fix: Update that package to its patched version.
  • Serious CVE-2020-13927 Authentication bypass in Apache Airflow
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2020-13927). Fix: Update that package to its patched version.
  • Serious CVE-2022-38649 OS Command Injection in Apache Airflow
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2022-38649). Fix: Update that package to its patched version.
  • Serious CVE-2022-40189 OS Command Injection in Apache Airflow
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2022-40189). Fix: Update that package to its patched version.
  • Serious CVE-2023-22884 Command Injection in Apache Airflow and Apache Airflow MySQL Provider
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2023-22884). Fix: Update that package to its patched version.
  • Serious CVE-2023-25754 Apache Airflow vulnerable to Privilege Context Switching Error
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2023-25754). Fix: Update that package to its patched version.
  • Serious CVE-2022-24439 GitPython: improper user input validation leads into a RCE
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2022-24439). Fix: Update that package to its patched version.
  • Serious CVE-2023-40267 GitPython: Insecure non-multi options in clone and clone_from is not blocked
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2023-40267). Fix: Update that package to its patched version.
  • Serious CVE-2019-6446 numpy: crafted serialized object passed in numpy.load() in pickle python module allows arbitrary code execution
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2019-6446). Fix: Update that package to its patched version.
  • Serious CVE-2017-18342 PyYAML: yaml.load() API could execute arbitrary code
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2017-18342). Fix: Update that package to its patched version.
  • Serious CVE-2020-14343 PyYAML: incomplete fix for CVE-2020-1747
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2020-14343). Fix: Update that package to its patched version.
  • Serious CVE-2019-7164 python-sqlalchemy: SQL Injection when the order_by parameter can be controlled
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2019-7164). Fix: Update that package to its patched version.
  • Serious CVE-2019-7548 python-sqlalchemy: SQL Injection when the group_by parameter can be controlled
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2019-7548). Fix: Update that package to its patched version.
  • Serious CVE-2018-20060 python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2018-20060). Fix: Update that package to its patched version.
  • Worth fixing CVE-2017-15720 Improper Input Validation in Apache Airflow resulting in Remote Code Execution
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2017-15720). Fix: Update that package to its patched version.
  • Worth fixing CVE-2017-17835 Cross-Site Request Forgery (CSRF) in Apache Airflow
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2017-17835). Fix: Update that package to its patched version.
  • Worth fixing CVE-2018-20245 Improper Certificate Validation in Apache Airflow
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2018-20245). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-0229 Apache Airflow vulnerable to CSRF Attacks
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2019-0229). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-11978 Remote code execution (RCE) in Apache Airflow
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2020-11978). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-17526 Incorrect Session Validation in Apache Airflow
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2020-17526). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-24288 OS Command injection in Apache Airflow
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2022-24288). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-27949 Apache Airflow subject to Exposure of Sensitive Information
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2022-27949). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-40127 Apache Airflow vulnerable to OS Command Injection via example DAGs
    Pipfile.lock
    A package you depend on has a known security hole (CVE-2022-40127). Fix: Update that package to its patched version.
… 156 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 200 found · 20 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2019-149 In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow,
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2017-17836). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-15 An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resu
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2020-11981). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-16 An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious pay
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2020-11982). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-18 The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the de
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2020-13927). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-314 Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2023-25693). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-59 Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2023-25754). Fix: Update that package to its patched version.
  • Serious PYSEC-2025-87 Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2025-67895). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-2082 A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2026-33264). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-267 OS Command Injection in Apache Airflow
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2022-38649). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-268 Command Injection in Apache Airflow and Apache Airflow MySQL Provider
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2023-22884). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-270 OS Command Injection in Apache Airflow
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2022-40189). Fix: Update that package to its patched version.
  • Serious PYSEC-2022-42992 All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2022-24439). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-137 GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2023-40267). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-2161 GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options))
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2026-42284). Fix: Update that package to its patched version.
  • Serious PYSEC-2019-108 ** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2019-6446). Fix: Update that package to its patched version.
  • Serious PYSEC-2018-49 In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced fo
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2017-18342). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-142 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2020-14343). Fix: Update that package to its patched version.
  • Serious PYSEC-2019-123 SQLAlchemy before 1.3.0b3 allows SQL Injection via the order_by parameter. The fix (commit 30307c4) was applied only to the main branch and was never backported to the 1.2.x release line; all 1.2.x ve
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2019-7164). Fix: Update that package to its patched version.
  • Serious PYSEC-2019-124 SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2019-7548). Fix: Update that package to its patched version.
  • Serious PYSEC-2018-32 urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credential
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2018-20060). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2018-45 It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other bro
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2017-12614). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2019-142 In Apache Airflow before 1.10.2, a malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views.
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2018-20244). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2019-143 The LDAP auth backend (airflow.contrib.auth.backends.ldap_auth) prior to Apache Airflow 1.10.1 was misconfigured and contained improper checking of exceptions which disabled server certificate checkin
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2018-20245). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2019-147 In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2017-15720). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2019-148 In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.
    /workdirs/scan-6c667b22-8808-4992-9677-a0e6c713f0ce/Pipfile.lock
    A package you depend on has a known security hole (CVE-2017-17835). Fix: Update that package to its patched version.
… 175 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.