Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-40861

A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process (read-path attack — e.g. `/etc/passwd` or `airflow.cfg`) or (b) supply a `task_id` containing `..` sequences accepted by the Task SDK's `KEY_REGEX` (write-path attack), and in both cases the FileTaskHandler resolves the log path outside the configured `base_log_folder`, leaking or overwriting arbitrary files. Only affects deployments where the worker log folder is shared with the API server. Users are advised to upgrade to `apache-airflow` 3.2.2 or later. As a defense-in-depth mitigation, deploy the worker and API server with separate log volumes so that worker-controlled paths cannot reach the API server's filesystem.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 21.5%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-40861
  • Apache » Airflow » Version: N/A
    cpe:2.3:a:apache:airflow:-
  • Apache » Airflow » Version: 0.1
    cpe:2.3:a:apache:airflow:0.1
  • Apache » Airflow » Version: 0.2
    cpe:2.3:a:apache:airflow:0.2
  • Apache » Airflow » Version: 0.2.1
    cpe:2.3:a:apache:airflow:0.2.1
  • Apache » Airflow » Version: 0.2.2
    cpe:2.3:a:apache:airflow:0.2.2
  • Apache » Airflow » Version: 0.2.3
    cpe:2.3:a:apache:airflow:0.2.3
  • Apache » Airflow » Version: 0.3
    cpe:2.3:a:apache:airflow:0.3
  • Apache » Airflow » Version: 0.3.1
    cpe:2.3:a:apache:airflow:0.3.1
  • Apache » Airflow » Version: 0.3.2
    cpe:2.3:a:apache:airflow:0.3.2
  • Apache » Airflow » Version: 0.4
    cpe:2.3:a:apache:airflow:0.4
  • Apache » Airflow » Version: 0.4.1
    cpe:2.3:a:apache:airflow:0.4.1
  • Apache » Airflow » Version: 0.4.2
    cpe:2.3:a:apache:airflow:0.4.2
  • Apache » Airflow » Version: 0.4.3
    cpe:2.3:a:apache:airflow:0.4.3
  • Apache » Airflow » Version: 0.4.5
    cpe:2.3:a:apache:airflow:0.4.5
  • Apache » Airflow » Version: 0.4.6
    cpe:2.3:a:apache:airflow:0.4.6
  • Apache » Airflow » Version: 0.5.0
    cpe:2.3:a:apache:airflow:0.5.0
  • Apache » Airflow » Version: 1.0.0
    cpe:2.3:a:apache:airflow:1.0.0
  • Apache » Airflow » Version: 1.0.1
    cpe:2.3:a:apache:airflow:1.0.1
  • Apache » Airflow » Version: 1.1.0
    cpe:2.3:a:apache:airflow:1.1.0
  • Apache » Airflow » Version: 1.1.1
    cpe:2.3:a:apache:airflow:1.1.1
  • Apache » Airflow » Version: 1.10.0
    cpe:2.3:a:apache:airflow:1.10.0
  • Apache » Airflow » Version: 1.10.1
    cpe:2.3:a:apache:airflow:1.10.1
  • Apache » Airflow » Version: 1.10.10
    cpe:2.3:a:apache:airflow:1.10.10
  • Apache » Airflow » Version: 1.10.11
    cpe:2.3:a:apache:airflow:1.10.11
  • Apache » Airflow » Version: 1.10.12
    cpe:2.3:a:apache:airflow:1.10.12
  • Apache » Airflow » Version: 1.10.13
    cpe:2.3:a:apache:airflow:1.10.13
  • Apache » Airflow » Version: 1.10.14
    cpe:2.3:a:apache:airflow:1.10.14
  • Apache » Airflow » Version: 1.10.15
    cpe:2.3:a:apache:airflow:1.10.15
  • Apache » Airflow » Version: 1.10.2
    cpe:2.3:a:apache:airflow:1.10.2
  • Apache » Airflow » Version: 1.10.5
    cpe:2.3:a:apache:airflow:1.10.5
  • Apache » Airflow » Version: 1.10.6
    cpe:2.3:a:apache:airflow:1.10.6
  • Apache » Airflow » Version: 1.10.7
    cpe:2.3:a:apache:airflow:1.10.7
  • Apache » Airflow » Version: 1.10.8
    cpe:2.3:a:apache:airflow:1.10.8
  • Apache » Airflow » Version: 1.10.9
    cpe:2.3:a:apache:airflow:1.10.9
  • Apache » Airflow » Version: 1.2.0
    cpe:2.3:a:apache:airflow:1.2.0
  • Apache » Airflow » Version: 1.3.0
    cpe:2.3:a:apache:airflow:1.3.0
  • Apache » Airflow » Version: 1.4.0
    cpe:2.3:a:apache:airflow:1.4.0
  • Apache » Airflow » Version: 1.4.1
    cpe:2.3:a:apache:airflow:1.4.1
  • Apache » Airflow » Version: 1.5.0
    cpe:2.3:a:apache:airflow:1.5.0
  • Apache » Airflow » Version: 1.5.1
    cpe:2.3:a:apache:airflow:1.5.1
  • Apache » Airflow » Version: 1.5.2
    cpe:2.3:a:apache:airflow:1.5.2
  • Apache » Airflow » Version: 1.6.0
    cpe:2.3:a:apache:airflow:1.6.0
  • Apache » Airflow » Version: 1.6.1
    cpe:2.3:a:apache:airflow:1.6.1
  • Apache » Airflow » Version: 1.6.2
    cpe:2.3:a:apache:airflow:1.6.2
  • Apache » Airflow » Version: 1.7.0
    cpe:2.3:a:apache:airflow:1.7.0
  • Apache » Airflow » Version: 1.7.1
    cpe:2.3:a:apache:airflow:1.7.1
  • Apache » Airflow » Version: 1.7.1.1
    cpe:2.3:a:apache:airflow:1.7.1.1
  • Apache » Airflow » Version: 1.7.1.2
    cpe:2.3:a:apache:airflow:1.7.1.2
  • Apache » Airflow » Version: 1.7.1.3
    cpe:2.3:a:apache:airflow:1.7.1.3
  • Apache » Airflow » Version: 1.8.0
    cpe:2.3:a:apache:airflow:1.8.0
  • Apache » Airflow » Version: 1.8.1
    cpe:2.3:a:apache:airflow:1.8.1
  • Apache » Airflow » Version: 1.8.2
    cpe:2.3:a:apache:airflow:1.8.2
  • Apache » Airflow » Version: 1.9.0
    cpe:2.3:a:apache:airflow:1.9.0
  • Apache » Airflow » Version: 2.0.0
    cpe:2.3:a:apache:airflow:2.0.0
  • Apache » Airflow » Version: 2.0.1
    cpe:2.3:a:apache:airflow:2.0.1
  • Apache » Airflow » Version: 2.0.2
    cpe:2.3:a:apache:airflow:2.0.2
  • Apache » Airflow » Version: 2.1.0
    cpe:2.3:a:apache:airflow:2.1.0
  • Apache » Airflow » Version: 2.1.1
    cpe:2.3:a:apache:airflow:2.1.1
  • Apache » Airflow » Version: 2.1.2
    cpe:2.3:a:apache:airflow:2.1.2
  • Apache » Airflow » Version: 2.1.3
    cpe:2.3:a:apache:airflow:2.1.3
  • Apache » Airflow » Version: 2.1.4
    cpe:2.3:a:apache:airflow:2.1.4
  • Apache » Airflow » Version: 2.10.0
    cpe:2.3:a:apache:airflow:2.10.0
  • Apache » Airflow » Version: 2.10.1
    cpe:2.3:a:apache:airflow:2.10.1
  • Apache » Airflow » Version: 2.10.2
    cpe:2.3:a:apache:airflow:2.10.2
  • Apache » Airflow » Version: 2.10.3
    cpe:2.3:a:apache:airflow:2.10.3
  • Apache » Airflow » Version: 2.10.4
    cpe:2.3:a:apache:airflow:2.10.4
  • Apache » Airflow » Version: 2.10.5
    cpe:2.3:a:apache:airflow:2.10.5
  • Apache » Airflow » Version: 2.11.0
    cpe:2.3:a:apache:airflow:2.11.0
  • Apache » Airflow » Version: 2.11.1
    cpe:2.3:a:apache:airflow:2.11.1
  • Apache » Airflow » Version: 2.2.0
    cpe:2.3:a:apache:airflow:2.2.0
  • Apache » Airflow » Version: 2.2.1
    cpe:2.3:a:apache:airflow:2.2.1
  • Apache » Airflow » Version: 2.2.2
    cpe:2.3:a:apache:airflow:2.2.2
  • Apache » Airflow » Version: 2.2.3
    cpe:2.3:a:apache:airflow:2.2.3
  • Apache » Airflow » Version: 2.2.4
    cpe:2.3:a:apache:airflow:2.2.4
  • Apache » Airflow » Version: 2.2.5
    cpe:2.3:a:apache:airflow:2.2.5
  • Apache » Airflow » Version: 2.3.0
    cpe:2.3:a:apache:airflow:2.3.0
  • Apache » Airflow » Version: 2.3.1
    cpe:2.3:a:apache:airflow:2.3.1
  • Apache » Airflow » Version: 2.3.3
    cpe:2.3:a:apache:airflow:2.3.3
  • Apache » Airflow » Version: 2.3.4
    cpe:2.3:a:apache:airflow:2.3.4
  • Apache » Airflow » Version: 2.4.0
    cpe:2.3:a:apache:airflow:2.4.0
  • Apache » Airflow » Version: 2.4.1
    cpe:2.3:a:apache:airflow:2.4.1
  • Apache » Airflow » Version: 2.4.3
    cpe:2.3:a:apache:airflow:2.4.3
  • Apache » Airflow » Version: 2.5.0
    cpe:2.3:a:apache:airflow:2.5.0
  • Apache » Airflow » Version: 2.6.0
    cpe:2.3:a:apache:airflow:2.6.0
  • Apache » Airflow » Version: 2.6.1
    cpe:2.3:a:apache:airflow:2.6.1
  • Apache » Airflow » Version: 2.6.2
    cpe:2.3:a:apache:airflow:2.6.2
  • Apache » Airflow » Version: 2.6.3
    cpe:2.3:a:apache:airflow:2.6.3
  • Apache » Airflow » Version: 2.7.0
    cpe:2.3:a:apache:airflow:2.7.0
  • Apache » Airflow » Version: 2.7.1
    cpe:2.3:a:apache:airflow:2.7.1
  • Apache » Airflow » Version: 2.7.2
    cpe:2.3:a:apache:airflow:2.7.2
  • Apache » Airflow » Version: 2.7.3
    cpe:2.3:a:apache:airflow:2.7.3
  • Apache » Airflow » Version: 2.8.0
    cpe:2.3:a:apache:airflow:2.8.0
  • Apache » Airflow » Version: 2.8.1
    cpe:2.3:a:apache:airflow:2.8.1
  • Apache » Airflow » Version: 2.8.2
    cpe:2.3:a:apache:airflow:2.8.2
  • Apache » Airflow » Version: 2.8.3
    cpe:2.3:a:apache:airflow:2.8.3
  • Apache » Airflow » Version: 2.8.4
    cpe:2.3:a:apache:airflow:2.8.4
  • Apache » Airflow » Version: 2.9.0
    cpe:2.3:a:apache:airflow:2.9.0
  • Apache » Airflow » Version: 2.9.1
    cpe:2.3:a:apache:airflow:2.9.1
  • Apache » Airflow » Version: 2.9.2
    cpe:2.3:a:apache:airflow:2.9.2
  • Apache » Airflow » Version: 2.9.3
    cpe:2.3:a:apache:airflow:2.9.3
  • Apache » Airflow » Version: 3.0.0
    cpe:2.3:a:apache:airflow:3.0.0
  • Apache » Airflow » Version: 3.0.1
    cpe:2.3:a:apache:airflow:3.0.1
  • Apache » Airflow » Version: 3.0.2
    cpe:2.3:a:apache:airflow:3.0.2
  • Apache » Airflow » Version: 3.0.3
    cpe:2.3:a:apache:airflow:3.0.3
  • Apache » Airflow » Version: 3.0.4
    cpe:2.3:a:apache:airflow:3.0.4
  • Apache » Airflow » Version: 3.0.5
    cpe:2.3:a:apache:airflow:3.0.5
  • Apache » Airflow » Version: 3.0.6
    cpe:2.3:a:apache:airflow:3.0.6
  • Apache » Airflow » Version: 3.1.0
    cpe:2.3:a:apache:airflow:3.1.0
  • Apache » Airflow » Version: 3.1.1
    cpe:2.3:a:apache:airflow:3.1.1
  • Apache » Airflow » Version: 3.1.2
    cpe:2.3:a:apache:airflow:3.1.2
  • Apache » Airflow » Version: 3.1.3
    cpe:2.3:a:apache:airflow:3.1.3
  • Apache » Airflow » Version: 3.1.4
    cpe:2.3:a:apache:airflow:3.1.4
  • Apache » Airflow » Version: 3.1.5
    cpe:2.3:a:apache:airflow:3.1.5
  • Apache » Airflow » Version: 3.1.6
    cpe:2.3:a:apache:airflow:3.1.6
  • Apache » Airflow » Version: 3.1.7
    cpe:2.3:a:apache:airflow:3.1.7
  • Apache » Airflow » Version: 3.1.8
    cpe:2.3:a:apache:airflow:3.1.8
  • Apache » Airflow » Version: 3.2.0
    cpe:2.3:a:apache:airflow:3.2.0
  • Apache » Airflow » Version: 3.2.1
    cpe:2.3:a:apache:airflow:3.2.1


Contact Us

Shodan ® - All rights reserved