product of apache

apache-airflow-providers-fab

7 thingsrelated by NVD

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the…
CVE-2026-86466
Severity high
Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing…
CVE-2026-86462
Severity critical
Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented…
CVE-2026-82311
Severity critical
Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password…
CVE-2026-82310
Severity high
Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login…
CVE-2026-75156
Severity critical
In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced…
CVE-2026-59245
Severity high
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a…
CVE-2026-59243
Severity critical