Sensitive Cookie in HTTPS Session Without "Secure" Attribute Affecting apache-airflow-core package, versions [,3.2.2rc1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.35% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWCORE-17132622
  • published2 Jun 2026
  • disclosed1 Jun 2026
  • creditRan (@eddieran)

Introduced: 1 Jun 2026

CVE-2026-41017  (opens in a new tab)
CWE-614  (opens in a new tab)

How to fix?

Upgrade apache-airflow-core to version 3.2.2rc1 or higher.

Overview

Affected versions of this package are vulnerable to Sensitive Cookie in HTTPS Session Without "Secure" Attribute due to the JWTRefreshMiddleware process setting the JWT authentication cookie without the Secure flag. An attacker can hijack user sessions by capturing the JWT cookie from an HTTP request and replaying it against the authenticated API.

Note: This is only exploitable if the deployment is configured with a TLS-terminating reverse proxy and the API server receives plaintext HTTP traffic from the proxy.

CVSS Base Scores

version 4.0
version 3.1