News · via oss-security
CVE-2026-82355: Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation
Posted by Rahul Vats on Sep 21 Severity: low Affected versions: - Apache Airflow 3.3.0 before 3.3.2 Description: When a request to the Airflow core API carries both a session cookie and an explicit…
