Open Source Security mailing list@oss_securityDisclosure
The message announces two newly identified CVEs in Apache Airflow, providing concise technical notes and links for further details, without indicating PoC, exploitation tools, active attacks or mitigation.
CVE@CVEnewDisclosure
The post announces CVE-2026-28779 for Apache Airflow, detailing that the session token cookie’s path is incorrectly hard‑coded to '/', potentially exposing session information. No PoC, exploit, active exploitation, patch, or false‑positive claim is mentioned.
CVEarity@CVEarityGeneral
The tweet merely announces the existence of CVE-2026-28779 affecting Apache, without providing any further technical or actionable information.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
The tweet highlights CVE‑2026‑28779, a session‑hijacking flaw in Apache Airflow due to cookie path handling, but provides no PoC, exploit code, patch, or evidence of active attacks.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
The tweet alerts about CVE‑2026‑28779, showing a session hijacking flaw in Apache Airflow due to cookie path handling; no patch, PoC, or exploitation evidence is provided.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The post merely references CVE‑2026‑28779 as a session‑token hijacking flaw in Apache Airflow, providing no further detail, proof of concept, or patch information.