Intel

AIKIDO-2026-548054

apache-airflow-providers-fab is vulnerable to Insufficient Session Expiration

Insufficient Session ExpirationCVE-2026-82311 Published 3 days ago

98

Critical Risk

This Affects:

PYTHONapache-airflow-providers-fab
2.4.2 - 3.8.1
Fixed in 3.9.0
Are you affected? Scan for Free

TL;DR

The FAB provider's password-reset flow does not delete a user's existing session tokens when their password is reset. A session created before the reset keeps working after the reset, defeating the point of forcing a password change. This lets continued access persist through a token that a reset was meant to revoke. The fix deletes the user's existing sessions as part of the password-reset flow.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and rely on a password reset to cut off a compromised account's existing session.

Background info

apache-airflow-providers-fab is vulnerable to Insufficient Session Expiration in versions 2.4.2 - 3.8.1.

How to fix this

Upgrade the apache-airflow-providers-fab library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform