Open Source Security mailing list@oss_securityDisclosure
Two new Apache Airflow CVEs are announced—CVE‑2026‑26929 involving wildcard DagVersion listing bypass and CVE‑2026‑28563 involving DAG authorization bypass—alongside links to community discussion threads, but no PoC, exploit, patch, or false‑positive claim is provided.
CVE@CVEnewDisclosure
Apache Airflow versions 3.1.0 through 3.1.7 expose the full DAG dependency graph via the /ui/dependencies endpoint, potentially leaking data from unauthorized DAGs.
CVEarity@CVEarityGeneral
The tweet announces a new CVE (CVE‑2026‑28563) affecting Apache but provides no technical details, exploits, or mitigation advice.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
The alert announces CVE-2026-28563, a DAG authorization bypass in Apache Airflow, and provides an Intel report link, but offers no further exploit or mitigation details.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A newly reported information disclosure vulnerability (CVE-2026-28563) affects Apache Airflow 3.1.0‑3.1.7’s DAG dependencies endpoint; no PoC, exploit, or patch details are disclosed.