Severity: low 

Affected versions:

- Apache Airflow (apache-airflow) before 3.2.1

Description:

The asset dependency graph did not restrict nodes by the viewer's DAG read 
permissions: a user with read access to at least one DAG could browse the asset 
graph for any other asset in the deployment and learn the existence and names 
of DAGs and assets outside their authorized scope.

Users are recommended to upgrade to version 3.2.1, which fixes this issue.

Credit:

Saurabh (finder)
Jarek Potiuk (remediation developer)

References:

https://github.com/apache/airflow/pull/65273
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-40690

Reply via email to