Session Management Flaw in Apache Airflow Core API
CVE-2026-86473
Currently unrated
What is CVE-2026-86473?
A session management flaw in the Core API of Apache Airflow allows an attacker to exploit the logout endpoint. When a client logs out using an Authorization bearer header, the logout response does not invalidate the session token. This behavior can allow attackers who have previously acquired a valid token to continue accessing the system, even after the legitimate user has logged out. The vulnerability specifically affects API clients that utilize bearer tokens rather than browser session cookies, making it critical for users to upgrade to Apache Airflow version 3.3.2 or later to ensure proper session invalidation.
Affected Version(s)
Apache Airflow 3.0.0 < 3.3.2