Database/Control plane, storage & DevOps
Apache Airflow: /assets/events returns asset events for every DAG, ignoring per-DAG access control
Impact
Airflow is the orchestration layer many GPU fleets use to drive training and batch inference pipelines, and per-DAG access control is the mechanism that keeps one team's pipelines invisible to another. The /assets/events endpoint returned asset events for every DAG in the deployment with no authorization filter, so any authenticated user with asset-read access could enumerate source DAG ids, task ids, run ids and timestamps for pipelines they cannot otherwise see. The count query was also unfiltered, so total_entries and pagination leaked the existence of hidden DAGs even without reading rows. This is information disclosure about who runs what on the cluster, not code execution - but on a shared cluster it maps out other tenants' job structure and cadence.
Who can reach it
Any authenticated Airflow user holding asset-read access, over the API. No special configuration is needed; deployments that rely on per-DAG access control to separate teams or tenants are affected by default.
What to do
Upgrade to apache-airflow 3.3.2 or later. This is a control-plane component upgrade: restart the API server and scheduler. GPU nodes are untouched and no workload drain is required.
References
Related entries
- Jenkins core: crafted XML submission lets a read-only user create user objects on the controllerCVE-2026-84646 · Jenkins core (XML deserialization, user objects as nested field values)Medium
- Jenkins core: unescaped map keys let a user inject arbitrary fields into JSON and Python API responsesCVE-2026-84655 · Jenkins core (REST API JSON and Python serialization, unescaped map keys)Medium
- Jenkins core: missing permission check exposes build parameters of jobs a user cannot otherwise seeCVE-2026-84656 · Jenkins core (build parameter access, missing Item/Read permission check)Medium
- Jenkins Script Security Plugin: form submission exposes the script approval configuration to attackersCVE-2026-84658 · Jenkins Script Security Plugin (script approval configuration)Medium
- Jenkins Script Security Plugin: missing permission check lets attackers disable global sandbox enforcementCVE-2026-84659 · Jenkins Script Security Plugin (global sandbox enforcement setting)Medium
- Jenkins LDAP plugin: Stapler data binding lets a low-privileged user make the controller connect to any URLCVE-2026-84662 · Jenkins LDAP plugin (Stapler data binding, attacker-specified connection URL)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.