Intel

AIKIDO-2026-679612

apache-airflow-providers-fab is vulnerable to Insufficient Session Expiration

Insufficient Session ExpirationCVE-2026-82310 Published 3 days ago

72

High Risk

This Affects:

PYTHONapache-airflow-providers-fab
2.0.0 - 3.8.1
Fixed in 3.9.0
Are you affected? Scan for Free

TL;DR

Deactivating a user account in the FAB provider does not revoke tokens that were already issued to that account. A token issued before deactivation keeps authenticating successfully after the account has been deactivated. This leaves a path for continued access through an account an administrator believed was cut off. The fix revokes a user's outstanding tokens when their account is deactivated.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and rely on deactivating a user account to immediately cut off that user's API/token access.

Background info

apache-airflow-providers-fab is vulnerable to Insufficient Session Expiration in versions 2.0.0 - 3.8.1.

How to fix this

Upgrade the apache-airflow-providers-fab library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform