Echo: apache-airflow: security update to 3.3.0

medium Tenable Self-Hosted Container Security Plugin ID 465423

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag
filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source`
and `dep.target` fields of trigger / sensor dependency entries. An authenticated UI user with read
permission on some Dags could enumerate the identifiers of other Dags they were not authorized to read by
inspecting the dependency graph for trigger / sensor references. Affects deployments that rely on per-Dag
read scoping to keep Dag identifiers private across teams. This is a residual gap in the fix for
CVE-2026-28563, which filtered the top-level Dag key but did not propagate the filter into the trigger /
sensor dep-source / dep-target fields. Users who already upgraded for CVE-2026-28563 should additionally
upgrade to `apache-airflow` 3.3.0 or later to cover the residual trigger / sensor dependency leak.
(CVE-2026-48891)

Solution

Update the apache-airflow library and its related packages to version 3.3.0 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-48891

Plugin Details

Severity: Medium

ID: 465423

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2026-48891

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/6/2026

Vulnerability Publication Date: 7/7/2026

Reference Information

CVE: CVE-2026-48891