Apache Airflow Keycloak provider

2 known vulnerabilities in Apache Airflow Keycloak provider, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-76187 CVSS 9.8 critical Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client…
  • CVE-2026-76186 CVSS 9.1 critical Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token…