When a request to the Airflow core API carries both a session cookie and an explicit token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over cookie. The request then executes -- and is r
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Airflow | 3.3.0< 3.3.2 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Airflow | 3.3.0 ~ 3.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94301 | 9.8 CRITICAL | Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2 |
| CVE-2026-47321 | 7.5 HIGH | Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate |
| CVE-2026-91863 | Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows den | |
| CVE-2026-91864 | Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory | |
| CVE-2026-91865 | Apache Neethi: Crafted policy references cause exponential expansion during normalization | |
| CVE-2026-91866 | Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial | |
| CVE-2026-91867 | Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang t | |
| CVE-2026-75158 | Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag autho | |
| CVE-2026-86473 | Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocabl |
No comments yet