
CVE-2026-30898: Apache Airflow: Bad example of BashOperator shell injection via dag_run.conf https://www.openwall.com/lists/oss-security/2026/04/17/7 CVE-2026-32228: Apache Airflow: Users with asset materialization permissions could trigger Dags they had no access to https://www.openwall.com/lists/oss-security/2026/04/17/8
Post summary
The post announces two new Apache Airflow CVEs, detailing a BashOperator shell injection via dag_run.conf and an access-control flaw that permits unauthorized DAG execution.


