Apache Airflow 1.10 lifecycle

Current status

standard supportlow

Apache Airflow 1.10 is currently in standard support.

Security: 15 tracked advisories affecting this line · 2 in CISA KEV. Details below — lifecycle and vulnerability status are separate.

Official lifecycle source: Apache Airflow GitHub Releases

Support phase
standard support
End of life
Not officially published
Latest release
1.10.15
Released
17 Mar 2021

At a glance

Version line
1.10
Initial release
17 Jul 2019
Lifecycle phase
standard support
Latest stable
1.10.15
Latest release date
17 Mar 2021
EOL
Not officially published
Risk
low
Releases tracked
11

Lifecycle timeline

Phases from published LifecyclePeriod records. Missing phases are not inferred.

  1. Release

    17 Jul 2019

  2. standard supportcurrent

    17 Jul 2019 → —

    Source: Apache Airflow GitHub Releases

Apache Airflow 1.10 is currently in standard support.

Upgrade options

Newer supported Apache Airflow version lines from CompatHub lifecycle data. Compatibility and security context use existing evidence only.

You are on Apache Airflow 1.10

Supported

Supported upgrade options

Open full upgrade planner for Apache Airflow 1.10

Known exploited vulnerabilities

CVE entries that CISA lists in the Known Exploited Vulnerabilities catalogue, including due dates and ransomware use when published. CVSS shown when NVD enrichment is available.

  • CVE-2020-13927Known exploited

    Apache Airflow's Experimental API Authentication Bypass

    CISA KEV:
    listed · added 2022-01-18 · due 2022-07-18
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-1056, CWE-1188, CWE-306
    Affected:
    <1.10.11
    Fixed in:
    1.10.11
    Source:
    CISA KEV · Advisory
  • CVE-2020-11978Known exploited

    Apache Airflow Command Injection

    CISA KEV:
    listed · added 2022-01-18 · due 2022-07-18
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-78
    Affected:
    <1.10.11
    Fixed in:
    1.10.11
    Source:
    CISA KEV · Advisory

Security

Advisories affecting Apache Airflow 1.10 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
2
Highest CVSS
9.8
  • CVE-2020-13927Known exploited

    Apache Airflow's Experimental API Authentication Bypass

    CISA KEV:
    listed · added 2022-01-18 · due 2022-07-18
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-1056, CWE-1188, CWE-306
    Affected:
    <1.10.11
    Fixed in:
    1.10.11
    Source:
    CISA KEV · Advisory
  • CVE-2020-11978Known exploited

    Apache Airflow Command Injection

    CISA KEV:
    listed · added 2022-01-18 · due 2022-07-18
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-78
    Affected:
    <1.10.11
    Fixed in:
    1.10.11
    Source:
    CISA KEV · Advisory
  • CVE-2026-59244

    Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-59242

    Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-54183

    Apache Airflow: Airflow Variables were not masked in the UI for authenticated users

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68968

    Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68969

    Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68970

    Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68971

    Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68076

    Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68868

    Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables

    Affected:
    <22.3.0
    Fixed in:
    22.3.0
    Source:
    OSV source · Advisory
  • CVE-2026-68872

    Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-scope guard bypass resolves another team's Connection or Variable

    Affected:
    <9.34.0
    Fixed in:
    9.34.0
    Source:
    OSV source · Advisory
  • CVE-2026-68871

    Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves another team's Connection or Variable

    Affected:
    <4.5.1
    Fixed in:
    4.5.1
    Source:
    OSV source · Advisory
  • CVE-2026-68870

    Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: team-scope guard bypass resolves another team's Connection or Variable

    Affected:
    <14.1.0
    Fixed in:
    14.1.0
    Source:
    OSV source · Advisory
  • CVE-2026-59243

    Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)

    Affected:
    <3.7.3
    Fixed in:
    3.7.3
    Source:
    OSV source · Advisory

Latest release

1.10.15

Released 17 Mar 2021 · stable

https://github.com/apache/airflow/releases/tag/1.10.15

Previous releases

  • 1.10.14

    10 Dec 2020

  • 1.10.13

    25 Nov 2020

  • 1.10.12

    25 Aug 2020

Release history

11 concrete releases tracked for this line.

VersionRelease dateChannelSource
1.10.1517 Mar 2021stableSource
1.10.1410 Dec 2020stableSource
1.10.1325 Nov 2020stableSource
1.10.1225 Aug 2020stableSource
1.10.1110 Jul 2020stableSource
1.10.109 Apr 2020stableSource
1.10.919 Feb 2020stableSource
1.10.87 Feb 2020stableSource
1.10.724 Dec 2019stableSource
1.10.54 Sept 2019stableSource
1.10.317 Jul 2019stableSource

Release activity

Total releases
11
Last 30 days
0
Last 90 days
0
Avg. interval
~61 days
Most recent
17 Mar 2021

Should I use this version?

Suitable for new deployments

Apache Airflow 1.10 is currently supported (standard support).

Version comparison

Compact comparison against the nearest relevant release lines.

1.103.3
Statusstandard supportstandard support
Latest release1.10.153.3.1
EOLNot publishedNot published
Risklowlow

Compatibility

Evidence-backed compatibility results involving Apache Airflow 1.10. Only combinations CompatHub can evaluate from upstream sources are listed.

Open Compatibility Explorer →

Sources

Where this information comes from.

Lifecycle sources

Release sources

Data coverage

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Releases tracked
11
Lifecycle periods
1
EOL
Not officially published
Provenance records
2
Data last checked
2 Sept 2026
Latest source update
2 Sept 2026

EOL: Not officially published

Other Apache Airflow versions