Package profile
apache-airflow-providers-apache-kafka
- Summary: Provider package apache-airflow-providers-apache-kafka for Apache Airflow
- Author: Apache Software Foundation <dev@airflow.apache.org>
- License: Apache-2.0
- Documentation: https://airflow.apache.org/docs/apache-airflow-providers-apache-kafka/2.0.0
- Source: https://github.com/apache/airflow
- Number of releases: 79
- First release: 1.0.0rc1 on 2023-04-21
- Latest release: 2.0.0 on 2026-09-14
- Latest release size: 43.0 KB (pure Python wheel)
1 known vulnerabilityLatest: PYSEC-2026-3986 — Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka client which invokes them. Deployments that have enabled the Kafka event producer — `dag_run_events_enabled` or `task_instance_events_enabled`, both disabled by default — build that client inside the scheduler process, so a user whose only privilege is editing Airflow connections gains arbitrary code execution in the control plane; the Airflow security model limits connection-configuration users to code execution on workers, not the scheduler. Deployments using Google Managed Kafka are not affected, because that code path overwrites any user-supplied `oauth_cb`; plain brokers and Amazon MSK are exposed. Users are recommended to upgrade to apache-airflow-providers-apache-kafka 2.0.0 or later, which adds an allowlist configuration option for connection-string callbacks. View all →
Dependencies
Apache-airflow-providers-apache-kafka has 7 dependencies, 3 of which optional.Circular dependencies detected in the dependency tree: apache-airflow-providers-common-compat → apache-airflow, apache-airflow-providers-standard → apache-airflow, apache-airflow-providers-common-sql → apache-airflow, apache-airflow-providers-smtp → apache-airflow, apache-airflow-providers-common-io → apache-airflow, apache-airflow-core → apache-airflow-task-sdk. Hidden from the diagram below to keep it an acyclic graph.
Dependent packages
| Package | Optional | Group |
|---|---|---|
| apache-airflow | true | all |
| apache-airflow-providers-common-messaging | true | apache-kafka |
Similar packages
- apache-airflow-providers-salesforceProvider package apache-airflow-providers-salesforce for Apache Airflow
- apache-airflow-providers-common-compatProvider package apache-airflow-providers-common-compat for Apache Airflow
- apache-airflow-providers-opsgenieProvider package apache-airflow-providers-opsgenie for Apache Airflow
- apache-airflow-providers-httpProvider package apache-airflow-providers-http for Apache Airflow
- apache-airflow-providers-airbyteProvider package apache-airflow-providers-airbyte for Apache Airflow
- apache-airflow-providers-fabProvider package apache-airflow-providers-fab for Apache Airflow
- apache-airflow-providers-standardProvider package apache-airflow-providers-standard for Apache Airflow