Severity: Medium 

Affected versions:

- Apache Airflow (apache-airflow) 3.0.0 before 3.1.8

Description:

Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies 
is set to path=/ regardless of the configured [webserver] base_url or [api] 
base_url.
This allows any application co-hosted under the same domain to capture valid 
Airflow session tokens from HTTP request headers, allowing full session 
takeover without attacking Airflow itself.

Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which 
resolves this issue.

Credit:

Daniel Wolf (finder)
Daniel Wolf (remediation developer)

References:

https://github.com/apache/airflow/pull/62771
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-28779

Reply via email to