-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The core vulnerability stems from missing consistency checks for dag_id parameters across multiple request sources. The GitHub PR #34366 explicitly adds a check_dag_consistency function to validate parameter alignment, indicating these were previously missing. The clear endpoint is specifically called out in vulnerability descriptions as an attack vector for unauthorized DAG clearing. Both the validation function and endpoint handler are directly implicated by the patch and CVE description.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| apache-airflow | pip | < 2.7.2 | 2.7.2 |
Ongoing coverage of React2Shell