Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5w6h-pjw6-wvc6 | apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session Fixation |
Mon, 11 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache apache-airflow-providers-keycloak
|
|
| CPEs | cpe:2.3:a:apache:apache-airflow-providers-keycloak:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache apache-airflow-providers-keycloak
|
Mon, 20 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 20 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Apache Airflow: OAuth Login CSRF — Missing State Parameter in Keycloak Auth Manager | Apache Airflow Providers Keycloak: OAuth Login CSRF — Missing State Parameter in Keycloak Auth Manager |
Sat, 18 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow |
|
| Vendors & Products |
Apache
Apache airflow |
Sat, 18 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 18 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not use PKCE. An attacker with a Keycloak account in the same realm could deliver a crafted callback URL to a victim's browser and cause the victim to be logged into the attacker's Airflow session (login-CSRF / session fixation), where any credentials the victim subsequently stored in Airflow Connections would be harvestable by the attacker. Users are advised to upgrade `apache-airflow-providers-keycloak` to 0.7.0 or later. | |
| Title | Apache Airflow: OAuth Login CSRF — Missing State Parameter in Keycloak Auth Manager | |
| Weaknesses | CWE-352 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-04-20T16:17:53.543Z
Reserved: 2026-04-16T00:13:13.957Z
Link: CVE-2026-40948
Updated: 2026-04-20T16:17:46.616Z
Status : Analyzed
Published: 2026-04-18T14:16:10.897
Modified: 2026-05-11T15:09:48.010
Link: CVE-2026-40948
No data.
OpenCVE Enrichment
Updated: 2026-04-20T18:45:14Z
Github GHSA