Apache Apache-airflow-providers-fab — known CVE vulnerabilities
Every CVE whose affected-product data names Apache Apache-airflow-providers-fab, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVE-2026-59243 — CVSS 9.8 (critical): The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a…
CVE-2024-45033 — CVSS 8.1 (high): Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2…
CVE-2026-59245 — CVSS 8.1 (high): In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced…
CVE-2026-46745 — CVSS 5.3 (medium): Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to…