© 2025-2026 PySpect
First version without a known vulnerability: 10.17.0
Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
Fixed in: 10.17.0
Apache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer service
Fixed in: 2.6.1, 7.0.0
Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration
Fixed in: 7.0.0