← Retour à la recherche de CVE

CVE-2026-41017

Apache Airflow

Description

Apache Airflow-s `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy (e.g. nginx / Envoy / a managed load balancer that terminates TLS and forwards plaintext to the API server, the default cloud-native topology) would have the user-s session JWT replayed over any cleartext HTTP request to the same host. A network-positioned attacker (Wi-Fi MITM, hostile LAN, captive-portal proxy) could induce a logged-in user-s browser to issue an HTTP request to the deployment-s hostname and capture the JWT cookie out of that request, then replay it against the authenticated API. Affects deployments where the Airflow API server is reached through a TLS-terminating proxy and the cookie-s secure-by-default protection is load-bearing for session integrity. Users are advised to upgrade to `apache-airflow` 3.2.2 or later.

CVSS 5.9EPSS 0.35000000000000003%Risque 0.61
Voir la source
Publication
2026-06-01 09:16:18
Versions concernées
<3.2.2
Type
Core software
Dernière modification
2026-07-21 19:10:00
Vecteur
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N