Feed/CVE-2026-46745
CVE-2026-46745MEDIUMCVSS 5.3

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability

Published May 26, 2026·Updated Jun 30, 2026

NVD Description

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated.

Affected Packages (1)

apache-airflow-providers-fabPYPI
Fixed in 3.6.4

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free