
CVE-2026-34538: Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure) https://www.openwall.com/lists/oss-security/2026/04/09/9 CVE-2025-57735: Apache Airflow: Airflow Logout Not Invalidating JWT https://www.openwall.com/lists/oss-security/2026/04/09/16 Both are "Severity: low"
Post summary
The text lists two low‑severity Apache Airflow CVEs with short descriptors and links, but provides no PoC, exploit, patch, or active‑exploitation information.



