Apache Apache-airflow-providers-fab — known CVE vulnerabilities
Every CVE whose affected-product data names Apache Apache-airflow-providers-fab, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (10)
CVE-2026-59243 — CVSS 9.8 (critical): The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a…
CVE-2026-82311 — CVSS 9.8 (critical): Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented…
CVE-2026-75156 — CVSS 9.1 (critical): Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login…
CVE-2026-86462 — CVSS 9.1 (critical): Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing…
CVE-2024-45033 — CVSS 8.1 (high): Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2…
CVE-2026-86466 — CVSS 8.1 (high): Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the…
CVE-2026-59245 — CVSS 8.1 (high): In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced…
CVE-2026-82310 — CVSS 7.2 (high): Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password…
CVE-2026-46745 — CVSS 5.3 (medium): Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to…