← All credits
Claude Security Scans
7 vulnerability records and advisories credit this contributor.
CVE-2026-81914
Apache Airflow Google provider: Google Drive query injection via unescaped file and folder names
CVE-2026-81862
Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credentials in SQL text, task logs and Teradata query logs
CVE-2026-81930
Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain
CVE-2026-82355
Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation
CVE-2026-86792
Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration
CVE-2026-76187
Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT
CVE-2026-76186
Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity