Apache Airflow 1.7 lifecycle

Current status

end of lifehigh

Apache Airflow 1.7 reached end of life on 17 Jul 2019. Security and bug fixes are no longer provided by the project according to published lifecycle data.

This line is end of life.

Plan your upgrade →

Security: 15 tracked advisories affecting this line · 2 in CISA KEV. Details below — lifecycle and vulnerability status are separate.

Official lifecycle source: Apache Airflow GitHub Releases

Support phase
end of life
End of life
17 Jul 2019
Latest release
1.7.0
Released
28 Mar 2016

At a glance

Version line
1.7
Initial release
28 Mar 2016
Lifecycle phase
end of life
Latest stable
1.7.0
Latest release date
28 Mar 2016
EOL
17 Jul 2019
Risk
high
Releases tracked
1

Lifecycle timeline

Phases from published LifecyclePeriod records. Missing phases are not inferred.

  1. Release

    28 Mar 2016

  2. standard support

    28 Mar 2016 → 17 Jul 2019

    Source: Apache Airflow GitHub Releases

  3. end of lifecurrent

    17 Jul 2019 → —

    Source: Apache Airflow GitHub Releases

Apache Airflow 1.7 reached end of life on 17 Jul 2019. Security and bug fixes are no longer provided by the project according to published lifecycle data.

Upgrade options

Newer supported Apache Airflow version lines from CompatHub lifecycle data. Compatibility and security context use existing evidence only.

You are on Apache Airflow 1.7

End of lifeEOL 17 July 2019

Supported upgrade options

Open full upgrade planner for Apache Airflow 1.7

Known exploited vulnerabilities

CVE entries that CISA lists in the Known Exploited Vulnerabilities catalogue, including due dates and ransomware use when published. CVSS shown when NVD enrichment is available.

  • CVE-2020-13927Known exploited

    Apache Airflow's Experimental API Authentication Bypass

    CISA KEV:
    listed · added 2022-01-18 · due 2022-07-18
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-1056, CWE-1188, CWE-306
    Affected:
    <1.10.11
    Fixed in:
    1.10.11
    Source:
    CISA KEV · Advisory
  • CVE-2020-11978Known exploited

    Apache Airflow Command Injection

    CISA KEV:
    listed · added 2022-01-18 · due 2022-07-18
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-78
    Affected:
    <1.10.11
    Fixed in:
    1.10.11
    Source:
    CISA KEV · Advisory

Security

Advisories affecting Apache Airflow 1.7 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
2
Highest CVSS
9.8
  • CVE-2020-13927Known exploited

    Apache Airflow's Experimental API Authentication Bypass

    CISA KEV:
    listed · added 2022-01-18 · due 2022-07-18
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    9.8 (critical) · NVD
    CWE:
    CWE-1056, CWE-1188, CWE-306
    Affected:
    <1.10.11
    Fixed in:
    1.10.11
    Source:
    CISA KEV · Advisory
  • CVE-2020-11978Known exploited

    Apache Airflow Command Injection

    CISA KEV:
    listed · added 2022-01-18 · due 2022-07-18
    Required action:
    Apply updates per vendor instructions.
    CVSS:
    8.8 (high) · NVD
    CWE:
    CWE-78
    Affected:
    <1.10.11
    Fixed in:
    1.10.11
    Source:
    CISA KEV · Advisory
  • CVE-2026-59244

    Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-59242

    Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-54183

    Apache Airflow: Airflow Variables were not masked in the UI for authenticated users

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68968

    Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68969

    Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68970

    Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68971

    Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68076

    Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68868

    Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables

    Affected:
    <22.3.0
    Fixed in:
    22.3.0
    Source:
    OSV source · Advisory
  • CVE-2026-68872

    Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-scope guard bypass resolves another team's Connection or Variable

    Affected:
    <9.34.0
    Fixed in:
    9.34.0
    Source:
    OSV source · Advisory
  • CVE-2026-68871

    Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves another team's Connection or Variable

    Affected:
    <4.5.1
    Fixed in:
    4.5.1
    Source:
    OSV source · Advisory
  • CVE-2026-68870

    Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: team-scope guard bypass resolves another team's Connection or Variable

    Affected:
    <14.1.0
    Fixed in:
    14.1.0
    Source:
    OSV source · Advisory
  • CVE-2026-59243

    Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)

    Affected:
    <3.7.3
    Fixed in:
    3.7.3
    Source:
    OSV source · Advisory

Latest release

1.7.0

Released 28 Mar 2016 · stable

https://github.com/apache/airflow/releases/tag/1.7.0

Release history

1 concrete release tracked for this line.

VersionRelease dateChannelSource
1.7.028 Mar 2016stableSource

Release activity

Total releases
1
Last 30 days
0
Last 90 days
0
Most recent
28 Mar 2016

Should I use this version?

Not recommended for new deployments

Upgrade to a currently supported release line. Recommended target: Apache Airflow 3.3.

Version comparison

Compact comparison against the nearest relevant release lines.

1.73.3
Statusend of lifestandard support
Latest release1.7.03.3.1
EOLJul 2019Not published
Riskhighlow

Sources

Where this information comes from.

Lifecycle sources

Release sources

Data coverage

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Releases tracked
1
Lifecycle periods
2
EOL
Known
Provenance records
3
Data last checked
2 Sept 2026
Latest source update
2 Sept 2026

Other Apache Airflow versions