CVE-2026-76187
- EPSS 0.2%
- Veröffentlicht 16.09.2026 09:10:57
- Zuletzt bearbeitet 18.09.2026 14:27:16
Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow. No allowlist restricts which client ids ...
CVE-2026-76186
- EPSS 0.21%
- Veröffentlicht 16.09.2026 09:09:57
- Zuletzt bearbeitet 18.09.2026 14:26:45
Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthent...
CVE-2026-40948
- EPSS 0.33%
- Veröffentlicht 18.04.2026 13:22:41
- Zuletzt bearbeitet 11.05.2026 15:09:48
The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not use PKCE. An attacker with a Keycloak account in the same realm co...