Reliance on Cookies without Validation and Integrity Checking Affecting apache-airflow-providers-keycloak package, versions [,0.10.0rc1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.81% (56th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWPROVIDERSKEYCLOAK-19882865
  • published17 Sept 2026
  • disclosed16 Sept 2026
  • creditUnknown

Introduced: 16 Sep 2026

NewCVE-2026-76186  (opens in a new tab)
CWE-565  (opens in a new tab)

How to fix?

Upgrade apache-airflow-providers-keycloak to version 0.10.0rc1 or higher.

Overview

apache-airflow-providers-keycloak is a Provider package apache-airflow-providers-keycloak for Apache Airflow

Affected versions of this package are vulnerable to Reliance on Cookies without Validation and Integrity Checking via get_user_from_token in keycloak_auth_manager.py, where Keycloak access and refresh tokens carried in separate _access_token and _refresh_token cookies are attached to a session without verifying that they belong to the same subject as the signed Airflow JWT. An attacker can pair their own valid Airflow session with another user's Keycloak token, causing every authorization decision to be made using the victim's Keycloak privileges while the session identity, audit records, and logs continue to reflect the attacker's own identity.

CVSS Base Scores

version 4.0
version 3.1