Skip to main content

Vendor/product archive

apache / apache-airflow-providers-fab CVEs

Beta · best-effort

4 CVEs tagged to apache / apache-airflow-providers-fab1 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-59245

Published Jul 13, 2026

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted…

CVSS 8.1 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-46745

Published May 25, 2026

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authenticatio…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-45033

Published Jan 8, 2025

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed w…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1