oss-sec mailing list archives

CVE-2026-40961: Apache Airflow: Open Redirect Bypass Vulnerability


From: Rahul Vats <rahulvats () apache org>
Date: Sun, 31 May 2026 11:37:43 +0000

Severity: low 

Affected versions:

- Apache Airflow (apache-airflow) 3.0.0 before 3.2.2

Description:

A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the 
`is_safe_url` check, enabling redirection from a trusted Airflow domain to an attacker-controlled origin. Users are 
advised to upgrade to `apache-airflow` 3.2.2 or later. As a defense-in-depth mitigation, deployment operators can place 
Airflow behind a reverse proxy that strips off-domain `next=` query parameters before they reach the login endpoint.

Credit:

Fushuling@secsys (finder)
RacerZ@secsys (finder)
Aritra Basu (remediation developer)

References:

https://github.com/apache/airflow/pull/65557
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-40961


Current thread: