CVE-2026-28779Disclosure(apache / airflow)

LOWCVSS 7.5 · HIGH

Signal is active with 6 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. This allows any application co-hosted under the same domain to capture valid Airflow session tokens from HTTP request headers, allowing full session takeover without attacking Airflow itself. Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 6 mentions across 1 observed day

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • 6 total mentions across 1 day

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline6 mentions / 1d
02356Mentions · 2026-03-17: 6Technical Details · 2026-03-17: 503-17
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets7 URLs
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    4 CVEs in Apache Airflow CVE-2026-30911: Execution API HITL Endpoints Missing Per-Task Authorization https://www.openwall.com/lists/oss-security/2026/03/17/2 CVE-2026-28779: Path of session token in cookie does not consider base_url - session hijacking https://www.openwall.com/lists/oss-security/2026/03/17/3 + next tweet

    Post summary

    The message announces two newly identified CVEs in Apache Airflow, providing concise technical notes and links for further details, without indicating PoC, exploitation tools, active attacks or mitigation.

    100601.0K
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28779 Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. Th… https://www.cve.org/CVERecord?id=CVE-2026-28779

    Post summary

    The post announces CVE-2026-28779 for Apache Airflow, detailing that the session token cookie’s path is incorrectly hard‑coded to '/', potentially exposing session information. No PoC, exploit, active exploitation, patch, or false‑positive claim is mentioned.

    00000140
    56.8K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-28779 🚨 Risk Level: Unknown 🧩 Affects: Apache Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-28779 #CVE-2026-28779 #CVE  #Apache #CyberSecurity #InfoSec https://t.co/tEk2fYzvwl

    Post summary

    The tweet merely announces the existence of CVE-2026-28779 affecting Apache, without providing any further technical or actionable information.

    0000033
    101 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28779 - Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications Intel Report: https://ift.tt/AsZugQa

    Post summary

    The tweet highlights CVE‑2026‑28779, a session‑hijacking flaw in Apache Airflow due to cookie path handling, but provides no PoC, exploit code, patch, or evidence of active attacks.

    0000041
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28779 - Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications Intel Report: https://ift.tt/6M3Q9q1

    Post summary

    The tweet alerts about CVE‑2026‑28779, showing a session hijacking flaw in Apache Airflow due to cookie path handling; no patch, PoC, or exploitation evidence is provided.

    0000039
    336 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28779 Session Token Hijacking Vulnerability in Apache Airflow 3.1.0-3.1.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28779

    Post summary

    The post merely references CVE‑2026‑28779 as a session‑token hijacking flaw in Apache Airflow, providing no further detail, proof of concept, or patch information.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more