VendorsApacheapache-airflow-providers-keycloakany version
Vulnerabilities

Apache Apache-airflow-providers-keycloak any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2026-76187
Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT
Published 2026-09-16 · Analyzed
9.8EPSS 0.010
CVE-2026-76186
Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity
Published 2026-09-16 · Analyzed
9.1EPSS 0.008
CVE-2026-40948
Apache Airflow Providers Keycloak: OAuth Login CSRF — Missing State Parameter in Keycloak Auth Manager
Published 2026-04-18 · Analyzed
5.4EPSS 0.004