Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 CVE-2026-42358

Apache Airflow: Variable masker depth-limit bypass returns cleartext nested secrets_CVE-2026-42358

A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `s...

Apache Software Foundation Apache Airflow CVE
MEDIUM 5.9 CVE-2026-41017

Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxy_CVE-2026-41017

Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an ...

Apache Software Foundation Apache Airflow 3.0.0 CVE
MEDIUM 4.3 CVE-2026-41014

Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints_CVE-2026-41014

The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API u...

Apache Software Foundation Apache Airflow 3.2.0 CVE
MEDIUM 6.5 CVE-2026-40861

Apache Airflow: Arbitrary File Read via Log Symlink following in FileTaskHandler_CVE-2026-40861

A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process (r...

Apache Software Foundation Apache Airflow CVE
MEDIUM 6.8 CVE-2026-0086

CVE-2026-0086_CVE-2026-0086

In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to lo...

Google Android 16-qpr2 CVE
MEDIUM 6.2 CVE-2026-0055

CVE-2026-0055_CVE-2026-0055

In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory ...

Google Android 16-qpr2 CVE
MEDIUM 6.8 CVE-2026-0048

CVE-2026-0048_CVE-2026-0048

In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could le...

Google Android 16-qpr2 CVE
MEDIUM 6.2 CVE-2026-0046

CVE-2026-0046_CVE-2026-0046

In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This...

Google Android 16 CVE
MEDIUM 4.3 CVE-2026-41115

Apache Kafka: Improper Authorization in CONSUMER_GROUP_DESCRIBE API_CVE-2026-41115

An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates ...

Apache Software Foundation Apache Kafka 4.0.0 CVE
MEDIUM 6.3 CVE-2026-49943

CVE-2026-49943_CVE-2026-49943

CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a...

NIC BIRD CVE