Apache Software Foundation Apache Airflow Keycloak Provider vulnerabilities
2 known vulnerabilities affecting apache_software_foundation/apache_airflow_keycloak_provider.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2
Vulnerabilities
Page 1 of 1
CVE-2026-76187P2CRITICALCVSS 9.8fixed in 0.10.02026-09-16
CVE-2026-76187 [CRITICAL] CWE-287 CVE-2026-76187: Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials gr
Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow. No allowlist restricts which client ids may authenticate, so the credentials of an unrelated application that happens to share the realm ar
nvd
CVE-2026-76186P2CRITICALCVSS 9.1fixed in 0.10.02026-09-16
CVE-2026-76186 [CRITICAL] CWE-565 CVE-2026-76186: Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity
Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated cookies, and never checks that the two describe the same subject. A user who holds any valid
nvd