Loading…
Tuesday October 6, 2026 14:00 - 14:45 IDT
Apache Airflow has evolved far beyond a cron replacement. It now powers core machine learning workflows, data engineering platforms, CI/CD pipelines, and enterprise automation systems.

With tens of millions of monthly downloads and global enterprise adoption, Airflow represents a high-value target. Its dynamic DAG execution model, Python-based operators, and extensive provider ecosystem create powerful capabilities and a significant attack surface.

This session presents research-backed insights and controlled demonstrations covering:

1. Exposure in the Wild

* Adoption scale and ecosystem growth
* Patterns of publicly exposed Airflow instances
* Observed vulnerable version distribution
* Common deployment mistakes

2. Vulnerability Classes

* Authorization and RBAC weaknesses
* Privilege escalation via unsafe DAG design
* Code execution surfaces in templating and operators
* Secret leakage through logs and variables
* Example DAG abuse
* Provider-level weaknesses
* Supply-chain risks in DAG CI/CD pipelines
* Misconfiguration patterns (root execution, open UI, permissive file systems)

3. Live Demonstrations (Isolated Lab Environment)

All demos are performed in a controlled Docker-based lab.

We will demonstrate:

* How low-privilege users can trigger unintended execution paths
* How secrets leak through logging misconfiguration
* How example DAGs expand the attack surface
* How unsafe provider parameters introduce injection risk

No public systems are targeted.

4. Defensive Playbook

* Secure DAG development practices
* Proper RBAC architecture
* Secret management integrations
* CI/CD enforcement for DAG review
* Log hygiene and detection controls
* Network isolation strategies
* Practical upgrade and patching strategy

5. Real-World Upgrade Challenges

Upgrading Airflow is not always straightforward. I will share operational lessons from attempting to migrate to newer secure versions.

Attendees leave with a practical hardening blueprint that goes beyond "just upgrade."

Speakers
avatar for Or Sahar

Or Sahar

Security Researcher | Reflectiz, Secure From Scratch
Or Sahar is a security researche, with two decades of experience in software development and security, she specialises in penetration testing, AI and Security research and application security.
Tuesday October 6, 2026 14:00 - 14:45 IDT
Hall A

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link