Apache-airflow-providers-fab
This hub aggregates every CVE we track for Apache-airflow-providers-fab, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
5
Critical
4
High
0
In CISA KEV
Severity distribution
CRITICAL5HIGH4MEDIUM1
Monthly trend
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
2
0
5
2024-102026-09
Latest CVEs
The 10 most recently published vulnerabilities affecting Apache-airflow-providers-fab.
- CVE-2026-86466Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated8.1
- CVE-2026-82310Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access7.2
- CVE-2026-86462Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions9.1
- CVE-2026-82311Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false9.8
- CVE-2026-75156Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass9.1
- CVE-2026-59243Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)9.8
- CVE-2026-59245Apache Airflow FAB provider: FAB auth manager: a DAG named "DAGs" hijacks the global all-DAGs permission (access_control privilege escalation via resource_name() collision)8.1
- CVE-2026-46745Apache Airflow FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap reachable via /auth/token5.3
- CVE-2024-45033Apache Airflow Fab Provider: Application does not invalidate session after password change via Airflow cli8.1
- CVE-2024-42447Apache Airflow Providers FAB: FAB provider 1.2.1 and 1.2.0 did not let user to logout for Airflow9.8
Product normalization is registry-driven with AI assist and human review. How it works