oss-security·2d agoCVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication#apache#qpid#broker-jCVE-2026-92609 6 sources
oss-security·5d agoCVE-2026-82355: Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation#apache-airflow#cve-2026-82355#session-fixationCVE-2026-82355 3 sources
oss-security·11d agoCVE-2026-86462: Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions#apache-airflow#cve#fab-providerCVE-2026-86462 3 sources