© 2025-2026 PySpect
First version without a known vulnerability: 3.2.2
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
Fixed in: 3.2.2
Apache Airflow allows code execution through crafted XCom payloads
Fixed in: 3.2.0
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
Fixed in: 3.2.0
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
Fixed in: 3.2.0
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
Fixed in: 3.2.0