Apache Apache-airflow-providers-keycloak — known CVE vulnerabilities
Every CVE whose affected-product data names Apache Apache-airflow-providers-keycloak, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (3)
CVE-2026-76187 — CVSS 9.8 (critical): Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client…
CVE-2026-76186 — CVSS 9.1 (critical): Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token…
CVE-2026-40948 — CVSS 5.4 (medium): The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on…