CVE-2026-28779: Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications

Published Mar 17, 2026
·
Updated

Apache Airflow versions 3.1.0 through 3.1.7 session token (token) in cookies is set to path=/ regardless of the configured [webserver] baseurl or [api] baseurl. This allows any application co-hosted under the same domain to capture valid Airflow session tokens from HTTP request headers, allowing full session takeover without attacking Airflow itself.

Users are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.

Affected Software

4 affected componentsFixes available
apache/airflow>=3.1.0<3.1.7
apache/airflow>=3.1.8
Apache Airflow>=3.0.0<3.1.8
pip/apache-airflow>=3.0.0<3.1.8
3.1.8

Event History

Mar 17, 2026
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
DescriptionWeakness
Data Sourced
via NVD·11:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·12:30 PM
Data Sourced
via GitHub·12:30 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-28779?

CVE-2026-28779 is considered a high severity vulnerability due to its potential for session hijacking.

2

How do I fix CVE-2026-28779?

To fix CVE-2026-28779, upgrade Apache Airflow to version 3.1.8 or later, where the issue has been addressed.

3

What versions of Apache Airflow are affected by CVE-2026-28779?

CVE-2026-28779 affects Apache Airflow versions 3.1.0 through 3.1.7.

4

How does CVE-2026-28779 enable session hijacking?

CVE-2026-28779 allows session hijacking because the session token in cookies is set to a path that does not respect the configured base_url.

5

What components are involved in the CVE-2026-28779 vulnerability?

CVE-2026-28779 specifically involves the webserver and API components of Apache Airflow.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203