
CVE-2025-54550: Apache Airflow: RCE by race condition in example_xcom dag https://www.openwall.com/lists/oss-security/2026/04/15/1 CVE-2026-25219: Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access https://www.openwall.com/lists/oss-security/2026/04/15/3
Post summary
The text announces two Apache Airflow vulnerabilities: one enabling remote code execution via a race condition, and another exposing sensitive Azure Service Bus connection strings to users with view privileges. No PoC, exploit, or patch details are provided.


