Apache Airflow has evolved far beyond a cron replacement. It now powers core machine learning workflows, data engineering platforms, CI/CD pipelines, and enterprise automation systems.
With tens of millions of monthly downloads and global enterprise adoption, Airflow represents a high-value target. Its dynamic DAG execution model, Python-based operators, and extensive provider ecosystem create powerful capabilities and a significant attack surface.
This session presents research-backed insights and controlled demonstrations covering:
1. Exposure in the Wild
* Adoption scale and ecosystem growth * Patterns of publicly exposed Airflow instances * Observed vulnerable version distribution * Common deployment mistakes
2. Vulnerability Classes
* Authorization and RBAC weaknesses * Privilege escalation via unsafe DAG design * Code execution surfaces in templating and operators * Secret leakage through logs and variables * Example DAG abuse * Provider-level weaknesses * Supply-chain risks in DAG CI/CD pipelines * Misconfiguration patterns (root execution, open UI, permissive file systems)
3. Live Demonstrations (Isolated Lab Environment)
All demos are performed in a controlled Docker-based lab.
We will demonstrate:
* How low-privilege users can trigger unintended execution paths * How secrets leak through logging misconfiguration * How example DAGs expand the attack surface * How unsafe provider parameters introduce injection risk
No public systems are targeted.
4. Defensive Playbook
* Secure DAG development practices * Proper RBAC architecture * Secret management integrations * CI/CD enforcement for DAG review * Log hygiene and detection controls * Network isolation strategies * Practical upgrade and patching strategy
5. Real-World Upgrade Challenges
Upgrading Airflow is not always straightforward. I will share operational lessons from attempting to migrate to newer secure versions.
Attendees leave with a practical hardening blueprint that goes beyond "just upgrade."
Security Researcher | Reflectiz, Secure From Scratch
Or Sahar is a security researche, with two decades of experience in software development and security, she specialises in penetration testing, AI and Security research and application security.