Apache
Apache-airflow-providers-fab: vulnerabilidades y CVE
Apache-airflow-providers-fab tiene 10 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses8
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86466 | Alta (8.1) | 0.37% | — | 16 sept 2026 | Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity… |
| CVE-2026-82310 | Alta (7.2) | 1.0% | — | 16 sept 2026 | Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to… |
| CVE-2026-86462 | Crítica (9.1) | 0.83% | — | 16 sept 2026 | Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's… |
| CVE-2026-82311 | Crítica (9.8) | 0.98% | — | 16 sept 2026 | Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login… |
| CVE-2026-75156 | Crítica (9.1) | 0.38% | — | 8 sept 2026 | Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with… |
| CVE-2026-59243 | Crítica (9.8) | 0.64% | — | 29 jul 2026 | The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass… |
| CVE-2026-59245 | Alta (8.1) | 0.60% | — | 13 jul 2026 | In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG… |
| CVE-2026-46745 | Media (5.3) | 0.76% | — | 25 may 2026 | Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to… |
| CVE-2024-45033 | Alta (8.1) | 0.95% | — | 8 ene 2025 | Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed with admin CLI, the sessions for that user… |
| CVE-2024-42447 | Crítica (9.8) | 0.93% | — | 5 ago 2024 | Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.