Apache Software Foundation Apache Airflow Fab Provider vulnerabilities
3 known vulnerabilities affecting apache_software_foundation/apache_airflow_fab_provider.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-59245P3HIGHCVSS 8.1fixed in 3.7.22026-07-13
CVE-2026-59245 [HIGH] CWE-269 CVE-2026-59245: In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-
In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named `DAGs` exists an
nvd
CVE-2023-40273P3HIGHCVSS 8.0fixed in 1.5.22023-08-23
CVE-2023-40273 [HIGH] CWE-384 CVE-2023-40273: The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webs
The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the session of the user. Other than manually cleaning the session database (for database session backend), or changing the secure_key and restarting the webse
nvd
CVE-2026-46745P3MEDIUMCVSS 5.3fixed in 3.6.42026-05-25
CVE-2026-46745 [MEDIUM] CWE-90 CVE-2026-46745: Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated.
cvelistv5nvd