CVE-2023-29247: Apache Airflow

Medium severity, CVSS 5.4. EPSS: 2% chance of exploitation in the next 30 days.

Task instance details page in the UI is vulnerable to a stored XSS.This issue affects Apache Airflow: before 2.6.0.

Affected products

  • Apache Airflow: before 2.6.0 (fixed in 2.6.0)

Published 2023-05-08. Last modified 2026-06-17.