THREAT OPS › Threat News › [NVD] CVE-2026-49296 (MEDIUM 6.5) — Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire source file without redacting Dags the
[NVD] CVE-2026-49296 (MEDIUM 6.5) — Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire source file without redacting Dags the
CVE-2026-49296 CVSS: 6.5 MEDIUM Published: 2026-07-07T10:16:41.603
Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire source file without redacting Dags the caller was not authorized to read, bypassing per-DA
Indicators of compromise
- CVE-2026-49296cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-49296