Skip to content

fix(deps): vuln apache-airflow (minor → 3.2.2) [providers/opensearch] - #33

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/uv/opensearch/6-1783382869
Draft

fix(deps): vuln apache-airflow (minor → 3.2.2) [providers/opensearch]#33
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/uv/opensearch/6-1783382869

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: Critical-severity security update — 1 package upgraded (MINOR changes included)

Manifests changed:

  • providers/opensearch (uv)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
apache-airflow 3.0.0 3.2.2 minor Direct 7 CRITICAL, 11 HIGH, 34 MEDIUM, 3 LOW

Security Details

🚨 Critical & High Severity (18 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
apache-airflow PYSEC-2026-184 critical - 3.0.0 3.2.2 -
apache-airflow PYSEC-2023-314 critical - 3.0.0 3.1.1 -
apache-airflow PYSEC-2026-275 critical Apache Airflow Sqoop Provider Improper Input Validation vulnerability 3.0.0 - -
apache-airflow CVE-2023-25693 critical - 3.0.0 - -
apache-airflow GHSA-j69x-v4wc-3fpf CRITICAL Apache Airflow Sqoop Provider Improper Input Validation vulnerability 3.0.0 - -
apache-airflow GHSA-c92r-g8j5-vhcx CRITICAL Apache Airflow: JWT token still valid after logout 3.0.0 3.2.0 -
apache-airflow PYSEC-2026-269 CRITICAL Apache Airflow: JWT token still valid after logout 3.0.0 3.2.0 -
apache-airflow GHSA-4fhm-p86v-hwpx HIGH Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications 3.0.0 3.1.8 -
apache-airflow PYSEC-2026-10 HIGH - 3.0.0 3.1.6 -
apache-airflow CVE-2025-68675 HIGH - 3.0.0 - -
apache-airflow GHSA-7c2f-r6gc-h92h HIGH Apache Airflow proxy credentials for various providers might leak in task logs 3.0.0 3.1.6 -
apache-airflow GHSA-q2hg-643c-gw8h HIGH Apache Airflow: RCE by race condition in example_xcom dag 3.0.0 3.2.0 -
apache-airflow PYSEC-2026-186 high - 3.0.0 3.2.2 -
apache-airflow GHSA-6ffj-2wg2-w45j HIGH Apache Airflow allows code execution through crafted XCom payloads 3.0.0 - -
apache-airflow PYSEC-2026-16 HIGH - 3.0.0 3.1.8 -
apache-airflow CVE-2026-28779 HIGH - 3.0.0 - -
apache-airflow GHSA-4m3h-wp5w-5hqh HIGH Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata 3.0.0 3.1.8 -
apache-airflow PYSEC-2026-13 HIGH - 3.0.0 3.2.0 -
ℹ️ Other Vulnerabilities (37)
Package CVE Severity Summary Unsafe Version Fixed In Case
apache-airflow PYSEC-2026-171 medium - 3.0.0 3.2.2 -
apache-airflow CVE-2026-26929 medium - 3.0.0 - -
apache-airflow PYSEC-2026-181 medium - 3.0.0 3.2.2 -
apache-airflow CVE-2026-24098 medium - 3.0.0 - -
apache-airflow PYSEC-2026-12 medium - 3.0.0 3.1.7 -
apache-airflow PYSEC-2026-14 medium - 3.0.0 3.1.8 -
apache-airflow PYSEC-2026-187 medium - 3.0.0 3.2.2 -
apache-airflow PYSEC-2026-173 medium - 3.0.0 3.2.2 -
apache-airflow CVE-2025-54831 medium - 3.0.0 - -
apache-airflow PYSEC-2025-85 medium - 3.0.0 - -
apache-airflow PYSEC-2026-172 medium - 3.0.0 3.2.2 -
apache-airflow PYSEC-2026-15 MODERATE - 3.0.0 3.1.8 -
apache-airflow CVE-2025-62402 MODERATE - 3.0.0 - -
apache-airflow GHSA-w7rc-q6cm-f5gm MODERATE Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions 3.0.0 3.2.1rc1 -
apache-airflow GHSA-4g48-54q2-fg7q MODERATE Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access 3.0.0 3.1.8 -
apache-airflow GHSA-q475-2pgm-7hvp MODERATE Apache Airflow: Connection sensitive details exposed to users with READ permissions 3.0.0 3.0.4 -
apache-airflow GHSA-gfw7-2v73-69wg MODERATE Apache Airflow error reporting may expose full kwargs 3.0.0 2.11.1 -
apache-airflow CVE-2026-28563 MODERATE - 3.0.0 - -
apache-airflow GHSA-w7cf-2pmc-5m4c MODERATE Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false 3.0.0 - -
apache-airflow GHSA-r7vr-m4jw-r794 MODERATE Apache Airflow has an authorization bypass in DagRun wait endpoint 3.0.0 3.2.0 -
apache-airflow PYSEC-2026-8 MODERATE - 3.0.0 3.2.0 -
apache-airflow PYSEC-2026-18 MODERATE - 3.0.0 3.2.0 -
apache-airflow GHSA-p3v3-229h-mc63 MODERATE Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record 3.0.0 3.2.1rc1 -
apache-airflow GHSA-273c-4g26-4jpm MODERATE Apache Airflow /api/v2/dagReports executes DAG Python in API 3.0.0 3.1.1 -
apache-airflow GHSA-x3fv-96qh-67m7 MODERATE Apache Airflow: DAG authorization bypass 3.0.0 3.1.8 -
apache-airflow CVE-2025-65995 MODERATE - 3.0.0 - -
apache-airflow GHSA-v3c9-j6h9-66v4 MODERATE Apache Airflow has a command injection vulnerability in "example_dag_decorator" 3.0.0 3.0.5 -
apache-airflow CVE-2025-54941 MODERATE - 3.0.0 - -
apache-airflow GHSA-j86x-fwp2-qh7v MODERATE Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI 3.0.0 3.2.0 -
apache-airflow GHSA-phv5-vq5p-qhp7 MODERATE Apache Airflow: JWT token appearing in logs 3.0.0 3.2.0 -
apache-airflow CVE-2025-62503 MODERATE - 3.0.0 - -
apache-airflow GHSA-gp5f-cx7h-8q6f MODERATE Apache Airflow's create action can upsert existing Pools/Connections/Variables 3.0.0 3.1.1 -
apache-airflow GHSA-5g2w-9f8g-g5q7 MODERATE Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users 3.0.0 3.1.7 -
apache-airflow PYSEC-2026-21 MODERATE - 3.0.0 3.2.0 -
apache-airflow PYSEC-2026-174 low - 3.0.0 3.2.2 -
apache-airflow GHSA-w9r4-94fj-xp69 LOW Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries 3.0.0 3.2.0 -
apache-airflow PYSEC-2026-19 LOW - 3.0.0 3.2.0 -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Author

Auto-rebase complete

Branch is up to date with main — rebased onto b3cc48d.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-94e5d1
dd-octo-sts-94e5d1 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/uv/opensearch/6-1783382869 branch from 86c4560 to 733b141 Compare August 3, 2026 14:58
@datadog-prod-us1-5

This comment has been minimized.

Co-authored-by: dd-octo-sts-94e5d1[bot] <266798093+dd-octo-sts-94e5d1[bot]@users.noreply.github.com>
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Author

Auto-rebase complete

Branch is up to date with main — rebased onto c7d7d70.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-94e5d1
dd-octo-sts-94e5d1 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/uv/opensearch/6-1783382869 branch from 733b141 to 923d53b Compare August 8, 2026 16:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants