apache / apache-airflow-providers-fab
8 known vulnerabilities in apache apache-airflow-providers-fab.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-82310 | Medium | 0.7% | 7.2 | Apache Airflow FAB provider: deactivating a user account does not stop tokens is… | |
| CVE-2026-82311 | Medium | 0.6% | 9.8 | Apache Airflow FAB provider: resetting a user's password does not delete that us… | |
| CVE-2026-59245 | Medium | 0.6% | 8.1 | In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided … | |
| CVE-2026-86462 | Medium | 0.5% | 9.1 | Apache Airflow FAB provider: changing a user's password through the Admin user-e… | |
| CVE-2026-59243 | Medium | 0.4% | 9.8 | The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` w… | |
| CVE-2026-86466 | Medium | 0.2% | 8.1 | Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager do… | |
| CVE-2026-75156 | Medium | 0.2% | 9.1 | Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the iss… | |
| CVE-2026-46745 | Low | 0.6% | 5.3 | Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability … |