airflow-core-2
Chainguard
Status
Impact
The werkzeug path traversal vulnerability (CVE-2024-49766) requires werkzeug 3.0.6+. However, airflow 2.11.0 requires werkzeug<3,>=2.0, and its dependency Connexion 2.14.2 requires werkzeug<2.3,>=1.0. Upgrading werkzeug to 3.0.6 breaks both airflow and Connexion compatibility. The fix requires upstream airflow to update to support werkzeug 3.x and update or remove the Connexion dependency.
Status
Status
Fixed version
2.11.0-r2Status