airflow-2
Chainguard
Status
Impact
The vulnerability in aiohttp is introduced via a transitive dependency from the ray package (v2.47.1, latest). Remediation is pending upstream updates from ray and a subsequent airflow release that includes the updated ray version. In the interim, we have proactively updated aiohttp to v3.12.14 wherever feasible.
Status