airflow-core-2
Chainguard
8.0
CVSS V3
Status
Impact
The werkzeug DoS vulnerability (CVE-2023-46136) requires werkzeug 2.3.8+ or 3.0.1+. However, airflow 2.11.0 ships with werkzeug 2.2.3, and its dependency Connexion 2.14.2 requires werkzeug<2.3,>=1.0. Upgrading werkzeug to 2.3.8 or higher breaks Connexion compatibility. The fix requires upstream airflow to update or remove the Connexion dependency to support newer werkzeug versions.
Status
Status
Fixed version
2.11.0-r2Status