https://seclists.org/oss-sec/2026/q2/687: CVE-2026-46745: Apache Airflow FAB provider: [ Security port ] LDAP Filter Injection in FAB Auth Manager _search_ldap achable via /auth/token (ZDS-223)
Published May 24, 2026
·Updated
Affected Software
1 affected component
pypi/apache-airflow-providers-fab<3.6.4
Frequently Asked Questions
1
What is the severity of CVE-2026-46745?
The severity of CVE-2026-46745 is classified as moderate.
2
Which versions of Apache Airflow FAB provider are affected by CVE-2026-46745?
Apache Airflow FAB provider versions before 3.6.4 are affected by CVE-2026-46745.
3
What type of vulnerability is CVE-2026-46745?
CVE-2026-46745 is an LDAP filter injection vulnerability.
4
How do I fix CVE-2026-46745?
To fix CVE-2026-46745, upgrade to Apache Airflow FAB provider version 3.6.4 or later.
5
Who can exploit CVE-2026-46745?
CVE-2026-46745 can be exploited by unauthenticated attackers.