Severity: low 

Affected versions:

- Apache Airflow (apache-airflow) 3.0.0 before 3.2.2

Description:

A bug in the login redirect route in Apache Airflow allowed authenticated users 
to craft URLs that bypassed the `is_safe_url` check, enabling redirection from 
a trusted Airflow domain to an attacker-controlled origin. Users are advised to 
upgrade to `apache-airflow` 3.2.2 or later. As a defense-in-depth mitigation, 
deployment operators can place Airflow behind a reverse proxy that strips 
off-domain `next=` query parameters before they reach the login endpoint.

Credit:

Fushuling@secsys (finder)
RacerZ@secsys (finder)
Aritra Basu (remediation developer)

References:

https://github.com/apache/airflow/pull/65557
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-40961

Reply via email to