PYSEC-2026-773
Dashboard / Vulnerabilities / PYSEC-2026-773
PYSEC-2026-773
Summary: Remote code execution in Apache Airflow Docker's Provider
Details: Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host. Disable loading of example DAGs or upgrade apache-airflow-providers-docker to 3.0.0 or above.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-38362, https://lists.apache.org/thread/614p38nf4gbk8xhvnskj9b1sqo2dknkb, http://www.openwall.com/lists/oss-security/2022/08/16/1, https://pypi.org/project/apache-airflow-providers-docker, https://github.com/advisories/GHSA-746v-hfh2-xphm
Affected packages
Package
Name: apache-airflow-providers-docker
Purl: pkg:pypi/apache-airflow-providers-docker
Affected ranges
Type: ECOSYSTEM
Events:
