News · via oss-security
CVE-2026-86473: Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry
Posted by Rahul Vats on Sep 21 Severity: low Affected versions: - Apache Airflow 3.0.0 before 3.3.2 Description: Apache Airflow: the Core API logout endpoint revokes only a session token presented as…
