apache-airflow-providers-fab
Provider package apache-airflow-providers-fab for Apache Airflow
Activity
- Latest release
- 3d ago
- Total releases
- 124
- Cadence
- ~5 days
- Last 12 months
- 52
Details
- License
- Apache-2.0
- First release
- Dec 23, 2023
| Version | Released | |
|---|---|---|
3.9.0rc1
pre
|
3.9.0rc1
pre
Dependencies (19)
+ 11 more |
|
3.8.1
patch
|
3.8.1
patch
Dependencies (19)
+ 11 more |
|
3.8.1rc2
pre
|
3.8.1rc2
pre
Dependencies (19)
+ 11 more |
|
3.8.1rc1
pre
|
3.8.1rc1
pre
Dependencies (19)
+ 11 more |
|
3.8.0
minor
|
3.8.0
minor
Dependencies (19)
+ 11 more |
|
3.8.0rc2
pre
|
3.8.0rc2
pre
Dependencies (19)
+ 11 more |
|
3.8.0rc1
pre
|
3.8.0rc1
pre
Dependencies (19)
+ 11 more |
|
3.7.3
patch
|
3.7.3
patch
Dependencies (19)
+ 11 more |
|
3.7.3rc1
pre
|
3.7.3rc1
pre
Dependencies (19)
+ 11 more |
|
3.7.2
patch
|
3.7.2
patch
Dependencies (19)
+ 11 more |
|
3.7.2rc1
pre
|
3.7.2rc1
pre
Dependencies (19)
+ 11 more |
|
3.7.1
patch
|
3.7.1
patch
Dependencies (19)
+ 11 more |
|
3.7.1rc1
pre
|
3.7.1rc1
pre
Dependencies (19)
+ 11 more |
|
3.7.0
minor
|
3.7.0
minor
Dependencies (19)
+ 11 more |
|
3.7.0rc1
pre
|
3.7.0rc1
pre
Dependencies (19)
+ 11 more |
|
3.6.5
patch
|
3.6.5
patch
Dependencies (19)
+ 11 more |
|
3.6.5rc1
pre
|
3.6.5rc1
pre
Dependencies (19)
+ 11 more |
|
3.6.4
patch
|
3.6.4
patch
Dependencies (19)
+ 11 more |
|
3.6.4rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.6.4rc1
pre
Dependencies (19)
+ 11 more |
|
3.6.3
patch
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.6.3
patch
Dependencies (18)
+ 10 more |
|
3.6.3rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.6.3rc1
pre
Dependencies (18)
+ 10 more |
|
3.6.2
patch
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.6.2
patch
Dependencies (18)
+ 10 more |
|
3.6.2rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.6.2rc1
pre
Dependencies (18)
+ 10 more |
|
3.6.1
patch
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.6.1
patch
Dependencies (18)
+ 10 more |
|
3.6.1rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.6.1rc1
pre
Dependencies (18)
+ 10 more |
|
3.6.0
minor
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.6.0
minor
Dependencies (17)
+ 9 more |
|
3.6.0rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.6.0rc1
pre
Dependencies (17)
+ 9 more |
|
3.5.0
minor
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.5.0
minor
Dependencies (16)
+ 8 more |
|
3.5.0rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.5.0rc1
pre
Dependencies (16)
+ 8 more |
|
3.4.0
minor
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.4.0
minor
Dependencies (17)
+ 9 more |
|
3.4.0rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.4.0rc1
pre
Dependencies (17)
+ 9 more |
|
1.5.4
patch
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.5.4
patch
Dependencies (9)
+ 1 more |
|
1.5.4rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.5.4rc1
pre
Dependencies (9)
+ 1 more |
|
3.3.0
minor
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.3.0
minor
Dependencies (17)
+ 9 more |
|
3.3.0rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.3.0rc1
pre
Dependencies (17)
+ 9 more |
|
3.2.0
minor
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.2.0
minor
Dependencies (17)
+ 9 more |
|
3.2.0rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.2.0rc1
pre
Dependencies (17)
+ 9 more |
|
3.1.2
patch
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.2
patch
Dependencies (16)
+ 8 more |
|
3.1.2rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.2rc1
pre
Dependencies (16)
+ 8 more |
|
3.1.1
patch
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.1
patch
Dependencies (17)
+ 9 more |
|
3.1.1rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.1rc1
pre
Dependencies (17)
+ 9 more |
|
3.1.0
minor
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.0
minor
Dependencies (17)
+ 9 more |
|
3.1.0rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.1.0rc1
pre
Dependencies (17)
+ 9 more |
|
3.0.3
patch
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.0.3
patch
Dependencies (17)
+ 9 more |
|
3.0.3rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.0.3rc1
pre
Dependencies (17)
+ 9 more |
|
3.0.2
patch
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.0.2
patch
Dependencies (17)
+ 9 more |
|
3.0.2rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.0.2rc1
pre
Dependencies (17)
+ 9 more |
|
3.0.1
patch
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.0.1
patch
Dependencies (17)
+ 9 more |
|
3.0.1rc1
pre
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.0.1rc1
pre
Dependencies (17)
+ 9 more |
|
3.0.0
major
1 CVE
CVE-2026-46745
PYSEC-2026-2366
GHSA-g283-w6fp-c4fc
Jul 13, 2026
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated attackers to exfiltrate directory data or bypass authentication. Upgrade to apache-airflow-providers-fab 3.6.4 or later. If immediate upgrade is not possible, disable LDAP authentication until the provider can be updated. Affected versions
1.0.0
1.0.0rc1
1.0.1
1.0.1.dev0
1.0.2
1.0.2.dev0
1.0.2.dev1
1.0.2.dev2
1.0.2b0
1.0.2rc1
1.0.3
1.0.3rc1
+ 94 more Show less
1.0.4
1.0.4rc1
1.1.0
1.1.0rc1
1.1.1
1.1.1rc1
1.2.0
1.2.0rc1
1.2.1
1.2.1rc1
1.2.2
1.2.2rc1
1.3.0
1.3.0rc1
1.4.0
1.4.0rc1
1.4.1
1.4.1rc1
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.1rc1
1.5.2
1.5.2rc1
1.5.3
1.5.3rc1
1.5.4
1.5.4rc1
2.0.0
2.0.0b1
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0rc4
2.0.1
2.0.1rc1
2.0.2
2.0.2rc1
2.0.2rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.2.1rc1
2.2.1rc2
2.3.0
2.3.0rc1
2.3.1
2.3.1rc1
2.4.0
2.4.0rc1
2.4.1
2.4.1rc1
2.4.2
2.4.2rc1
2.4.3
2.4.3rc1
2.4.4
2.4.4rc1
3.0.0
3.0.0rc1
3.0.0rc2
3.0.1
3.0.1rc1
3.0.2
3.0.2rc1
3.0.3
3.0.3rc1
3.1.0
3.1.0rc1
3.1.1
3.1.1rc1
3.1.2
3.1.2rc1
3.2.0
3.2.0rc1
3.3.0
3.3.0rc1
3.4.0
3.4.0rc1
3.5.0
3.5.0rc1
3.6.0
3.6.0rc1
3.6.1
3.6.1rc1
3.6.2
3.6.2rc1
3.6.3
3.6.3rc1
3.6.4rc1
Fixed in
3.6.4
References
Updated Jul 13, 2026 · Source: OSV.dev |
3.0.0
major
Dependencies (17)
+ 9 more |