Skip to main content
Loading…
    CVE-2026-28779 — Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. — CVE Database · The Intelligence Room