Apache Airflow version lifecycle

tool · Apache Software Foundation

Current status

supported

Supported version lines, end-of-life status, and latest releases for Apache Airflow — derived from official vendor sources, not third-party EOL aggregators.

Apache Airflow is a platform to programmatically author, schedule, and monitor workflows.

Security: 12 tracked advisories · 2 in CISA KEV. Details below — lifecycle and vulnerability status are separate.

Official site →

Version lines

21

Supported

3

EOL lines

18

Latest stable

3.3.1

2026-08-12

Releases tracked

89

At a glance

Latest release

3.3.1

Line 3.3

Recommended support line

3.3

standard support

Status

STANDARD SUPPORT

Newest supported: 3.3

EOL

Not published

Exact date not officially published

EOL lines include 3.2, 3.1, 3.0, 2.10, 2.9 (+13 more).

Recommended line: 3.3 (newest supported line with lowest lifecycle risk — not blindly “latest”).

Supported versions

3 currently supported release lines.

Version lineLifecycleLatest releaseReleasedEOLRisk
3.3
standard supportlow
3.3.12026-08-12Not officially publishedlow
2.11
standard supportlow
2.11.02025-05-20Not officially publishedlow
1.10
standard supportlow
1.10.152021-03-17Not officially publishedlow

End-of-life versions

Historical and unsupported release lines. Exact EOL dates shown only when published by the vendor.

Version lineLatest releaseLifecycleEOLRisk
3.23.2.2
end of lifehigh
2026-07-06high
3.13.1.8
end of lifehigh
2026-04-07high
3.03.0.6
end of lifehigh
2025-09-25high
2.102.10.5
end of lifehigh
2025-05-20high
2.92.9.3
end of lifehigh
2024-08-16high
2.82.8.4
end of lifehigh
2024-04-08high
2.72.7.3
end of lifehigh
2023-12-18high
2.62.6.3
end of lifehigh
2023-08-18high
2.52.5.3
end of lifehigh
2023-04-30high
2.42.4.3
end of lifehigh
2022-12-02high
2.32.3.4
end of lifehigh
2022-09-19high
2.22.2.5
end of lifehigh
2022-05-01high
2.12.1.4
end of lifehigh
2021-10-11high
2.02.0.2
end of lifehigh
2021-07-02high
1.71.7.0
end of lifehigh
2019-07-17high
1.61.6.2
end of lifehigh
2016-03-28high
1.51.5.2
end of lifehigh
2015-11-13high
1.41.4.0
end of lifehigh
2015-09-04high

Lifecycle overview

Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.

  • 3.3standard support
    standard support
  • 3.2end of life · EOL 2026-07-06
    standard supportend of life
  • 3.1end of life · EOL 2026-04-07
    standard supportend of life
  • 3.0end of life · EOL 2025-09-25
    standard supportend of life
  • 2.11standard support
    standard support
  • 2.10end of life · EOL 2025-05-20
    standard supportend of life
  • 2.9end of life · EOL 2024-08-16
    standard supportend of life
  • 2.8end of life · EOL 2024-04-08
    standard supportend of life
  • 2.7end of life · EOL 2023-12-18
    standard supportend of life
  • 2.6end of life · EOL 2023-08-18
    standard supportend of life
  • 2.5end of life · EOL 2023-04-30
    standard supportend of life
  • 2.4end of life · EOL 2022-12-02
    standard supportend of life
  • 2.3end of life · EOL 2022-09-19
    standard supportend of life
  • 2.2end of life · EOL 2022-05-01
    standard supportend of life
  • 2.1end of life · EOL 2021-10-11
    standard supportend of life
  • 2.0end of life · EOL 2021-07-02
    standard supportend of life

Showing 16 of 21 lines with lifecycle periods. See the directory below for the full list.

Known exploited vulnerabilities

CVE entries that CISA lists in the Known Exploited Vulnerabilities catalogue, including due dates and ransomware use when published. CVSS shown when NVD enrichment is available.

  • CVE-2020-13927Known exploited

    Apache Airflow's Experimental API Authentication Bypass

    CISA KEV:
    listed · added 2022-01-18 · due 2022-07-18
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-1056, CWE-1188, CWE-306
    Affected:
    <1.10.11
    Fixed in:
    1.10.11
    Source:
    CISA KEV · Advisory
  • CVE-2020-11978Known exploited

    Apache Airflow Command Injection

    CISA KEV:
    listed · added 2022-01-18 · due 2022-07-18
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-78
    Affected:
    <1.10.11
    Fixed in:
    1.10.11
    Source:
    CISA KEV · Advisory

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

Known vulnerabilities
12
Known exploited
2
Highest CVSS
9.8
  • CVE-2020-13927Known exploited

    Apache Airflow's Experimental API Authentication Bypass

    CISA KEV:
    listed · added 2022-01-18 · due 2022-07-18
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-1056, CWE-1188, CWE-306
    Affected:
    <1.10.11
    Fixed in:
    1.10.11
    Source:
    CISA KEV · Advisory
  • CVE-2020-11978Known exploited

    Apache Airflow Command Injection

    CISA KEV:
    listed · added 2022-01-18 · due 2022-07-18
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-78
    Affected:
    <1.10.11
    Fixed in:
    1.10.11
    Source:
    CISA KEV · Advisory
  • CVE-2026-59244

    Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-58076

    Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server

    Affected:
    >=3.3.0,<3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-59242

    Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-54183

    Apache Airflow: Airflow Variables were not masked in the UI for authenticated users

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-67260

    Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization

    Affected:
    >=3.3.0,<3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-67587

    Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget

    Affected:
    >=3.3.0,<3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-65017

    Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass)

    Affected:
    >=3.3.0,<3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68968

    Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68969

    Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68970

    Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory

Compare versions

Side-by-side view of the most relevant release lines.

3.32.111.10
Statusstandard supportstandard supportstandard support
Latest3.3.12.11.01.10.15
Released2026-08-122025-05-202021-03-17
EOLNot officially publishedNot officially publishedNot officially published
Risklowlowlow

Recent releases

Latest release date 2026-08-12 · 1 in last 30 days · 2 in last 90 days

Should I upgrade?

Current versions are supported

The preferred supported release line is Apache Airflow 3.3 (standard support).

Open upgrade planner →

Upgrade planning

Plan upgrades from Apache Airflow version lines that have newer supported options.

Compatibility

Evidence-backed Apache Airflow compatibility results from declared requirements — open the Compatibility Explorer for the full matrix.

Open Compatibility Explorer →

Data coverage

Version lines
21
Concrete releases
89
Supported lines
3
EOL lines
18
Lifecycle coverage
21/21
EOL coverage
18/21
Provenance coverage
21/21

Data freshness

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Data last checked
2026-09-02
Latest source update
2026-09-02

Sources

First-party and other registered sources contributing release and lifecycle facts.

Version line directory

Complete navigation into detailed version-line pages.

Currently supported

Version lineStatusLatest releaseReleasedEOL
3.3
standard supportlow
3.3.12026-08-12Not officially published
2.11
standard supportlow
2.11.02025-05-20Not officially published
1.10
standard supportlow
1.10.152021-03-17Not officially published

End of life

Version lineStatusLatest releaseReleasedEOL
3.2
end of lifehigh
3.2.22026-05-292026-07-06
3.1
end of lifehigh
3.1.82026-03-112026-04-07
3.0
end of lifehigh
3.0.62025-08-292025-09-25
2.10
end of lifehigh
2.10.52025-02-102025-05-20
2.9
end of lifehigh
2.9.32024-07-162024-08-16
2.8
end of lifehigh
2.8.42024-03-252024-04-08
2.7
end of lifehigh
2.7.32023-11-062023-12-18
2.6
end of lifehigh
2.6.32023-07-102023-08-18
2.5
end of lifehigh
2.5.32023-04-012023-04-30
2.4
end of lifehigh
2.4.32022-11-142022-12-02
2.3
end of lifehigh
2.3.42022-08-232022-09-19
2.2
end of lifehigh
2.2.52022-04-042022-05-01
2.1
end of lifehigh
2.1.42021-09-182021-10-11
2.0
end of lifehigh
2.0.22021-04-192021-07-02
1.7
end of lifehigh
1.7.02016-03-282019-07-17
1.6
end of lifehigh
1.6.22016-01-042016-03-28
1.5
end of lifehigh
1.5.22015-10-232015-11-13
1.4
end of lifehigh
1.4.02015-08-182015-09-04