VendorsApacheapache-airflow-providers-fabany version
Vulnerabilities

Apache Apache-airflow-providers-fab any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2026-82311
Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false
Published 2026-09-16 · Analyzed
9.8EPSS 0.010
CVE-2026-59243
Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)
Published 2026-07-29 · Analyzed
9.8EPSS 0.006
CVE-2026-86462
Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions
Published 2026-09-16 · Analyzed
9.1EPSS 0.008
CVE-2026-75156
Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass
Published 2026-09-08 · Analyzed
9.1EPSS 0.004
CVE-2024-45033
Apache Airflow Fab Provider: Application does not invalidate session after password change via Airflow cli
Published 2025-01-08 · Analyzed
8.1EPSS 0.010
CVE-2026-59245
Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)
Published 2026-07-13 · Modified
8.1EPSS 0.006
CVE-2026-86466
Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated
Published 2026-09-16 · Analyzed
8.1EPSS 0.004
CVE-2026-82310
Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access
Published 2026-09-16 · Analyzed
7.2EPSS 0.010
CVE-2026-46745
Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/token
Published 2026-05-25 · Analyzed
5.3EPSS 0.008