GPU VulnDB

Database/Control plane, storage & DevOps

Apache Airflow: /assets/events returns asset events for every DAG, ignoring per-DAG access control

CVSS 4.3CVE-2026-75158Control plane, storage & DevOpscurated

Impact

Airflow is the orchestration layer many GPU fleets use to drive training and batch inference pipelines, and per-DAG access control is the mechanism that keeps one team's pipelines invisible to another. The /assets/events endpoint returned asset events for every DAG in the deployment with no authorization filter, so any authenticated user with asset-read access could enumerate source DAG ids, task ids, run ids and timestamps for pipelines they cannot otherwise see. The count query was also unfiltered, so total_entries and pagination leaked the existence of hidden DAGs even without reading rows. This is information disclosure about who runs what on the cluster, not code execution - but on a shared cluster it maps out other tenants' job structure and cadence.

Who can reach it

Any authenticated Airflow user holding asset-read access, over the API. No special configuration is needed; deployments that rely on per-DAG access control to separate teams or tenants are affected by default.

What to do

Upgrade to apache-airflow 3.3.2 or later. This is a control-plane component upgrade: restart the API server and scheduler. GPU nodes are untouched and no workload drain is required.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.