Posted by Rahul Vats on Sep 21 Severity: low Affected versions: - Apache Airflow 3.0.0 before 3.3.2 Description: Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An attacker who already holds a copy of that...
CVE-2026-86473: Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/851
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.

