Apache Airflow 3.3 lifecycle

Current status

standard supportlow

Apache Airflow 3.3 is currently in standard support.

Security: 15 tracked advisories affecting this line. Details below — lifecycle and vulnerability status are separate.

Official lifecycle source: Apache Airflow GitHub Releases

Support phase
standard support
End of life
Not officially published
Latest release
3.3.1
Released
12 Aug 2026

At a glance

Version line
3.3
Initial release
6 Jul 2026
Lifecycle phase
standard support
Latest stable
3.3.1
Latest release date
12 Aug 2026
EOL
Not officially published
Risk
low
Releases tracked
2

Lifecycle timeline

Phases from published LifecyclePeriod records. Missing phases are not inferred.

  1. Release

    6 Jul 2026

  2. standard supportcurrent

    6 Jul 2026 → —

    Source: Apache Airflow GitHub Releases

Apache Airflow 3.3 is currently in standard support.

Security

Advisories affecting Apache Airflow 3.3 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
0
Highest CVSS
  • CVE-2026-59244

    Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-59242

    Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-54183

    Apache Airflow: Airflow Variables were not masked in the UI for authenticated users

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68968

    Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68969

    Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68970

    Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68971

    Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68076

    Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection

    Affected:
    <3.3.1
    Fixed in:
    3.3.1
    Source:
    OSV source · Advisory
  • CVE-2026-68868

    Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables

    Affected:
    <22.3.0
    Fixed in:
    22.3.0
    Source:
    OSV source · Advisory
  • CVE-2026-68872

    Apache Airflow Amazon provider: amazon SSM / Secrets Manager backends: team-scope guard bypass resolves another team's Connection or Variable

    Affected:
    <9.34.0
    Fixed in:
    9.34.0
    Source:
    OSV source · Advisory
  • CVE-2026-68871

    Apache Airflow Yandex provider: yandex Lockbox backend: team-scope guard bypass resolves another team's Connection or Variable

    Affected:
    <4.5.1
    Fixed in:
    4.5.1
    Source:
    OSV source · Advisory
  • CVE-2026-68870

    Apache Airflow Microsoft Azure provider: microsoft.azure Key Vault backend: team-scope guard bypass resolves another team's Connection or Variable

    Affected:
    <14.1.0
    Fixed in:
    14.1.0
    Source:
    OSV source · Advisory
  • CVE-2026-59243

    Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)

    Affected:
    <3.7.3
    Fixed in:
    3.7.3
    Source:
    OSV source · Advisory
  • CVE-2026-59245

    Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)

    Affected:
    <3.7.2
    Fixed in:
    3.7.2
    Source:
    OSV source · Advisory
  • CVE-2026-49486

    Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)

    Affected:
    <3.15.1
    Fixed in:
    3.15.1
    Source:
    OSV source · Advisory

Latest release

3.3.1

Released 12 Aug 2026 · stable

https://github.com/apache/airflow/releases/tag/3.3.1

Previous releases

  • 3.3.0

    6 Jul 2026

Release history

2 concrete releases tracked for this line.

VersionRelease dateChannelSource
3.3.112 Aug 2026stableSource
3.3.06 Jul 2026stableSource

Release activity

Total releases
2
Last 30 days
1
Last 90 days
2
Most recent
12 Aug 2026

Should I use this version?

Suitable for new deployments

Apache Airflow 3.3 is currently supported (standard support).

Version comparison

Compact comparison against the nearest relevant release lines.

3.33.2
Statusstandard supportend of life
Latest release3.3.13.2.2
EOLNot publishedJul 2026
Risklowhigh

Compatibility

Evidence-backed compatibility results involving Apache Airflow 3.3. Only combinations CompatHub can evaluate from upstream sources are listed.

Open Compatibility Explorer →

Sources

Where this information comes from.

Lifecycle sources

Release sources

Data coverage

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Releases tracked
2
Lifecycle periods
1
EOL
Not officially published
Provenance records
2
Data last checked
2 Sept 2026
Latest source update
2 Sept 2026

EOL: Not officially published

Other Apache Airflow versions