Intel

AIKIDO-2026-297701

apache-airflow-providers-fab is vulnerable to Origin Validation Error

Origin Validation ErrorCVE-2026-86466 Published Yesterday

81

High Risk

This Affects:

PYTHONapache-airflow-providers-fab
0.0.1 - 3.8.1
Fixed in 3.9.0
Are you affected? Scan for Free

TL;DR

The Authentik OAuth path in the FAB auth manager does not validate the origin of the OAuth response it receives before completing sign-in. A response redirected from an unintended origin can still be accepted and completed as a valid login. This lets sign-in proceed using an OAuth response Airflow should not have trusted. The fix validates the OAuth response's origin against the configured Authentik provider before completing sign-in.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and run Authentik configured as an OAuth login provider for the FAB auth manager.

Background info

apache-airflow-providers-fab is vulnerable to Origin Validation Error in versions 0.0.1 - 3.8.1.

How to fix this

Upgrade the apache-airflow-providers-fab library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform