PYSEC-2026-2369
apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session Fixation
Quick fix
PYSEC-2026-2369 — apache-airflow-providers-keycloak: upgrade to the fixed version with the command below.
pip install --upgrade 'apache-airflow-providers-keycloak>=0.7.0'Details
The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not use PKCE. An attacker with a Keycloak account in the same realm could deliver a crafted callback URL to a victim's browser and cause the victim to be logged into the attacker's Airflow session (login-CSRF / session fixation), where any credentials the victim subsequently stored in Airflow Connections would be harvestable by the attacker. Users are advised to upgrade `apache-airflow-providers-keycloak` to 0.7.0 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.1Fixed in: 0.7.0pip install --upgrade 'apache-airflow-providers-keycloak>=0.7.0'References
- https://nvd.nist.gov/vuln/detail/CVE-2026-40948[ADVISORY]
- https://github.com/apache/airflow/pull/64114[WEB]
- https://github.com/apache/airflow[PACKAGE]
- https://lists.apache.org/thread/kc0odpr70hbqhdb9ksnz42fkqz2xld9q[WEB]
- http://www.openwall.com/lists/oss-security/2026/04/17/14[WEB]
- https://pypi.org/project/apache-airflow-providers-keycloak[PACKAGE]
- https://github.com/advisories/GHSA-5w6h-pjw6-wvc6[ADVISORY]