/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-cjqh-m7mf-8p58

Published

Last updated

https://images.chainguard.dev/security/CGA-cjqh-m7mf-8p58
Package

airflow-core-2

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2023-46136
  • GHSA-hrfv-mqp8-q5rw

Severity

8.0

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2023-46136

Updates

Status

Pending upstream fix

Impact

The werkzeug DoS vulnerability (CVE-2023-46136) requires werkzeug 2.3.8+ or 3.0.1+. However, airflow 2.11.0 ships with werkzeug 2.2.3, and its dependency Connexion 2.14.2 requires werkzeug<2.3,>=1.0. Upgrading werkzeug to 2.3.8 or higher breaks Connexion compatibility. The fix requires upstream airflow to update or remove the Connexion dependency to support newer werkzeug versions.

Status

Under investigation

Status

Fixed

Fixed version

2.11.0-r2

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing