Cross-site Request Forgery (CSRF) Affecting apache-airflow-providers-keycloak package, versions [,0.7.0rc1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.33% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWPROVIDERSKEYCLOAK-16322795
  • published30 Apr 2026
  • disclosed18 Apr 2026
  • creditHaruki Oyama

Introduced: 18 Apr 2026

CVE-2026-40948  (opens in a new tab)
CWE-352  (opens in a new tab)

How to fix?

Upgrade apache-airflow-providers-keycloak to version 0.7.0rc1 or higher.

Overview

apache-airflow-providers-keycloak is a Provider package apache-airflow-providers-keycloak for Apache Airflow

Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) in the login authentication process due to missing generation and validation of the OAuth 2.0 state parameter and lack of PKCE support. An attacker with an account in the same Keycloak realm can cause a victim to be logged into the attacker's session by delivering a crafted callback URL, allowing the attacker to access any credentials the victim subsequently stores.

CVSS Base Scores

version 4.0
version 3.1