maven package report

Is apache:apache-airflow-providers-keycloak safe?

2 known vulnerabilities, worst severity CRITICAL.

cvss
9.1

how bad it is if exploited, out of 10

epss
0.80%

chance of exploitation in the next 30 days

xyz score
4.1

CyberXYZ composite, out of 10

fig. 01 — CVE-2026-76186, the advisory selected below

// advisories

CVE-2026-76186

CRITICAL

Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated cookies, and never checks that the two describe the same subject. A user who holds any valid Airflow login of their own, together with another

Affected
<0.10.0
Fixed in
not stated
Weakness
CWE-565
Published
2026-09-16
Source
NVD

NVDMITREreferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 02:39 UTC. The most recent advisory here was published 2026-09-16. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is apache:apache-airflow-providers-keycloak safe? maven package security report | CyberXYZ