VulnSea

apache-airflow-providers-fab vulnerabilities

CVEs whose affected-version data names the apache-airflow-providers-fab package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

10 CVEsRSS

CVE-2026-86466High· 8.1
6d ago

Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts

Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a …

Twilightapache · apache-airflow-providers-fabEPSS 0.36%via NVD
CVE-2026-82310High· 7.2
6d ago

Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation

Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to accept an existing, u…

Twilightapache · apache-airflow-providers-fabEPSS 0.98%via NVD
CVE-2026-86462Critical· 9.1
6d ago

Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions

Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie kee…

Midnightapache · apache-airflow-providers-fabEPSS 0.80%via NVD
CVE-2026-82311Critical· 9.8
6d ago

Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does

Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the sessi…

Midnightapache · apache-airflow-providers-fabEPSS 0.95%via NVD
CVE-2026-75156Critical· 9.1
2w ago

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth p…

Midnightapache · apache-airflow-providers-fabEPSS 0.27%via NVD
CVE-2026-59243Critical· 9.8PoC
1mo ago

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and lo…

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and lo…

Abyssalapache · apache-airflow-providers-fabEPSS 0.45%via NVD
CVE-2026-59245High· 8.1
2mo ago

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently gran…

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently gran…

Twilightapache · apache-airflow-providers-fabEPSS 0.60%via NVD
CVE-2026-46745Medium· 5.3
3mo ago

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability

Sunlitapache-airflow-providers-fab · apache-airflow-providers-fabEPSS 0.57%via OSV
CVE-2024-45033Low
1y ago

Apache Airflow Fab Provider Insufficient Session Expiration vulnerability

Apache Airflow Fab Provider Insufficient Session Expiration vulnerability

Sunlitapache-airflow-providers-fab · apache-airflow-providers-fabEPSS 0.95%via OSV
CVE-2024-42447Medium· 4.2
2y ago

Apache Airflow Providers FAB Insufficient Session Expiration vulnerability

Apache Airflow Providers FAB Insufficient Session Expiration vulnerability

Sunlitapache-airflow-providers-fab · apache-airflow-providers-fabEPSS 0.93%via OSV
apache-airflow-providers-fab vulnerabilities (CVEs) · VulnSea