CVE-2024-56373Disclosure(apache / airflow)

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which they should normally not be able to do, leading to potentially remote code execution in the context of web-server (server-side) as a result of a user viewing historical task information. The functionality responsible for that (log template history) has been disabled by default in 2.11.1 and users should upgrade to Airflow 3 if they want to continue to use log template history. They can also manually modify historical log file names if they want to see historical logs that were generated before the last log template change.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-24); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-24: 2Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Technical Details · 2026-02-24: 2Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2402-2803-01
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure2
2026-02-281
Disclosure1
2026-03-011
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2024-56373 DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which t… https://www.cve.org/CVERecord?id=CVE-2024-56373

    Post summary

    The text discloses that CVE-2024-56373 allows DAG authors to manipulate the Airflow 2 database and execute arbitrary code in the web-server context, but provides no PoC, exploit, patch, or evidence of active exploitation.

    01021131
    56.5K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2024-56373: Apache Airflow: SSTI to Code Execution in Airflow through Shared DB Information https://www.openwall.com/lists/oss-security/2026/02/23/3 DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context

    Post summary

    Apache Airflow 2 is vulnerable to a Server-Side Template Injection that allows DAG authors to manipulate the shared database and execute arbitrary code in the web‑server context.

    00020370
    4.4K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2024-56373 (CVSS:8.4, HIGH) is Analyzed. DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arb..https://nvd.nist.gov/vuln/detail/CVE-2024-56373 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet references CVE-2024-56373, noting its high CVSS score and that a DAG author can manipulate the Airflow 2 database to execute arbitrary code, but does not mention PoC, exploit code, active exploitation, or patches.

    0000057
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2024-56373 (CVSS:8.4, HIGH) is Analyzed. DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arb..https://nvd.nist.gov/vuln/detail/CVE-2024-56373 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post highlights CVE‑2024‑56373, noting its high CVSS score and explaining that a DAG author with extensive privileges can manipulate Airflow’s database to run arbitrary code, but it does not provide a PoC, exploit, or patch information.

    0000042
    173 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more