๐Ÿ” CVE Alert

CVE-2026-48726

MEDIUM 6.5

Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logout path

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
4th

A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` did not actually reach the underlying `revoke_token()` call, so the JWT remained accepted by the API server until its natural expiry. An attacker holding a previously-issued JWT for a logged-out user could continue to make authenticated API calls as that user. Affects deployments configured with `FabAuthManager` or `KeycloakAuthManager` (the bug does not affect SimpleAuthManager). This is a residual gap in the fix for CVE-2025-57735, which addressed cookie-side invalidation in PR #57992 / PR #61339 but did not cover the provider-side `revoke_token()` reachability in the FAB / Keycloak code paths. Users who already upgraded for CVE-2025-57735 should additionally upgrade to `apache-airflow` 3.2.2 or later to cover the FAB / Keycloak logout paths.

CWE CWE-613
Vendor apache software foundation
Product apache airflow
Published Jun 1, 2026
Last Updated Jun 2, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache airflow

Be the first to know when new medium vulnerabilities affecting apache software foundation apache airflow are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Airflow
0 < 3.2.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/airflow/pull/67289 cve.org: https://www.cve.org/CVERecord?id=CVE-2025-57735 lists.apache.org: https://lists.apache.org/thread/630jg4z6cjkv4m2yv2ljgmf1zhdj1vqx

Credits

Bernardo Curi (r3ngar_bugado) pierrejeambrun