Apache Airflow: Execution API HITL Endpoints Missing Per-Task Authorization
High severity
GitHub Reviewed
Published
Mar 17, 2026
to the GitHub Advisory Database
•
Updated Mar 18, 2026
Description
Published by the National Vulnerability Database
Mar 17, 2026
Published to the GitHub Advisory Database
Mar 17, 2026
Last updated
Mar 18, 2026
Reviewed
Mar 18, 2026
Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop (HITL) endpoints that allows any authenticated task instance to read, approve, or reject HITL workflows belonging to any other task instance.
Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.
References