← Back to CVEs
CVE-2026-28779
HIGH7.5
Description
Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. This allows any application co-hosted under the same domain to capture valid Airflow session tokens from HTTP request headers, allowing full session takeover without attacking Airflow itself. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.
CVE Details
CVSS v3.1 Score7.5
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published3/17/2026
Last Modified3/17/2026
Sourcenvd
Honeypot Sightings0
Affected Products
apache:airflow
Weaknesses (CWE)
CWE-668
References
https://github.com/apache/airflow/pull/62771(security@apache.org)
https://lists.apache.org/thread/r4n5znb8mcq14wo9v8ndml36nxlksdqb(security@apache.org)
http://www.openwall.com/lists/oss-security/2026/03/17/3(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.