VDB
Sign up
MEDIUM5.3

PYSEC-2026-2366

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability

Quick fix

PYSEC-2026-2366 — apache-airflow-providers-fab: upgrade to the fixed version with the command below.

pip install --upgrade 'apache-airflow-providers-fab>=3.6.4'

Details

Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/apache-airflow-providers-fab
Introduced in: 0Fixed in: 3.6.4
Fixpip install --upgrade 'apache-airflow-providers-fab>=3.6.4'

References