{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-28779",
        "tracking": {
            "current_release_date": "2026-03-23T03:19:43.678329Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-28779",
            "initial_release_date": "2026-03-17T10:38:46.664642Z",
            "revision_history": [
                {
                    "date": "2026-03-17T10:38:46.664642Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| Products created (1).| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-17T10:38:53.048031Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-03-17T11:25:26.927032Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| References created (2).| CWES updated (1)."
                },
                {
                    "date": "2026-03-17T11:25:33.058260Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-17T11:34:56.392607Z",
                    "number": "5",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-17T13:06:43.062876Z",
                    "number": "6",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (1).| References created (10)."
                },
                {
                    "date": "2026-03-17T13:06:46.362406Z",
                    "number": "7",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-17T14:32:16.507929Z",
                    "number": "8",
                    "summary": "CVSS created.| References created (1)."
                },
                {
                    "date": "2026-03-17T14:32:24.702156Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-17T14:38:47.510151Z",
                    "number": "10",
                    "summary": "CVSS created.| References created (1).| Unknown change."
                },
                {
                    "date": "2026-03-17T14:38:59.772573Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-17T15:03:08.128257Z",
                    "number": "12",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-17T15:03:15.070659Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-17T18:25:42.379216Z",
                    "number": "14",
                    "summary": "Products connected (1).| Product Identifiers created (1)."
                },
                {
                    "date": "2026-03-17T18:25:45.077505Z",
                    "number": "15",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-17T23:42:41.950233Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-18T17:08:18.448207Z",
                    "number": "17",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-18T17:08:26.193118Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-18T18:05:44.191409Z",
                    "number": "19",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (4)."
                },
                {
                    "date": "2026-03-18T18:35:34.302054Z",
                    "number": "20",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (46).| Product Identifiers created (48).| Products created (3).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-03-19T15:30:58.581958Z",
                    "number": "21",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-03-19T15:31:03.024313Z",
                    "number": "22",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:36:09.172604Z",
                    "number": "23",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:36:12.469002Z",
                    "number": "24",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "24"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<3.1.8",
                                "product": {
                                    "name": "vers:unknown/<3.1.8",
                                    "product_id": "CSAFPID-5834228"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Airflow"
                    }
                ],
                "category": "vendor",
                "name": "Apache"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/3.0.0|<3.1.8",
                                "product": {
                                    "name": "vers:semver/3.0.0|<3.1.8",
                                    "product_id": "CSAFPID-5831862"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Apache Airflow"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.0.0|<3.1.8",
                                "product": {
                                    "name": "vers:unknown/>=3.0.0|<3.1.8",
                                    "product_id": "CSAFPID-5838004",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "airflow"
                    }
                ],
                "category": "vendor",
                "name": "Apache Software Foundation"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.0.0|<3.1.8",
                                "product": {
                                    "name": "vers:unknown/>=3.0.0|<3.1.8",
                                    "product_id": "CSAFPID-5844740"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "airflow"
                    }
                ],
                "category": "vendor",
                "name": "Bitnami"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.0",
                                "product": {
                                    "name": "vers:unknown/3.0.0",
                                    "product_id": "CSAFPID-5441223",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.1",
                                "product": {
                                    "name": "vers:unknown/3.0.1",
                                    "product_id": "CSAFPID-5441233",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.1rc1",
                                "product": {
                                    "name": "vers:unknown/3.0.1rc1",
                                    "product_id": "CSAFPID-5441234",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.1rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.2",
                                "product": {
                                    "name": "vers:unknown/3.0.2",
                                    "product_id": "CSAFPID-5441235",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.2rc1",
                                "product": {
                                    "name": "vers:unknown/3.0.2rc1",
                                    "product_id": "CSAFPID-5441236",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.2rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.2rc2",
                                "product": {
                                    "name": "vers:unknown/3.0.2rc2",
                                    "product_id": "CSAFPID-5441237",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.2rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.3",
                                "product": {
                                    "name": "vers:unknown/3.0.3",
                                    "product_id": "CSAFPID-5441238",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.3rc1",
                                "product": {
                                    "name": "vers:unknown/3.0.3rc1",
                                    "product_id": "CSAFPID-5441239",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.3rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.3rc2",
                                "product": {
                                    "name": "vers:unknown/3.0.3rc2",
                                    "product_id": "CSAFPID-5441240",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.3rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.3rc3",
                                "product": {
                                    "name": "vers:unknown/3.0.3rc3",
                                    "product_id": "CSAFPID-5441241",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.3rc3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.3rc4",
                                "product": {
                                    "name": "vers:unknown/3.0.3rc4",
                                    "product_id": "CSAFPID-5441242",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.3rc4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.3rc5",
                                "product": {
                                    "name": "vers:unknown/3.0.3rc5",
                                    "product_id": "CSAFPID-5441243",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.3rc5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.3rc6",
                                "product": {
                                    "name": "vers:unknown/3.0.3rc6",
                                    "product_id": "CSAFPID-5441244",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.3rc6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.4",
                                "product": {
                                    "name": "vers:unknown/3.0.4",
                                    "product_id": "CSAFPID-5441245",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.4rc1",
                                "product": {
                                    "name": "vers:unknown/3.0.4rc1",
                                    "product_id": "CSAFPID-5441246",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.4rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.4rc2",
                                "product": {
                                    "name": "vers:unknown/3.0.4rc2",
                                    "product_id": "CSAFPID-5441247",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.4rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.5",
                                "product": {
                                    "name": "vers:unknown/3.0.5",
                                    "product_id": "CSAFPID-5441248",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.5rc1",
                                "product": {
                                    "name": "vers:unknown/3.0.5rc1",
                                    "product_id": "CSAFPID-5441249",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.5rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.5rc2",
                                "product": {
                                    "name": "vers:unknown/3.0.5rc2",
                                    "product_id": "CSAFPID-5441250",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.5rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.5rc3",
                                "product": {
                                    "name": "vers:unknown/3.0.5rc3",
                                    "product_id": "CSAFPID-5441251",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.5rc3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.6",
                                "product": {
                                    "name": "vers:unknown/3.0.6",
                                    "product_id": "CSAFPID-5441252",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.6rc1",
                                "product": {
                                    "name": "vers:unknown/3.0.6rc1",
                                    "product_id": "CSAFPID-5441253",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.6rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0.6rc2",
                                "product": {
                                    "name": "vers:unknown/3.0.6rc2",
                                    "product_id": "CSAFPID-5441254",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.0.6rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.0",
                                "product": {
                                    "name": "vers:unknown/3.1.0",
                                    "product_id": "CSAFPID-5441255",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.0b1",
                                "product": {
                                    "name": "vers:unknown/3.1.0b1",
                                    "product_id": "CSAFPID-5441256",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.0b1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.0b2",
                                "product": {
                                    "name": "vers:unknown/3.1.0b2",
                                    "product_id": "CSAFPID-5441257",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.0b2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.0rc1",
                                "product": {
                                    "name": "vers:unknown/3.1.0rc1",
                                    "product_id": "CSAFPID-5441258",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.0rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.0rc2",
                                "product": {
                                    "name": "vers:unknown/3.1.0rc2",
                                    "product_id": "CSAFPID-5441259",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.0rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.1",
                                "product": {
                                    "name": "vers:unknown/3.1.1",
                                    "product_id": "CSAFPID-5441260",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.1rc1",
                                "product": {
                                    "name": "vers:unknown/3.1.1rc1",
                                    "product_id": "CSAFPID-5441261",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.1rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.1rc2",
                                "product": {
                                    "name": "vers:unknown/3.1.1rc2",
                                    "product_id": "CSAFPID-5441262",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.1rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.2",
                                "product": {
                                    "name": "vers:unknown/3.1.2",
                                    "product_id": "CSAFPID-5441263",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.2rc1",
                                "product": {
                                    "name": "vers:unknown/3.1.2rc1",
                                    "product_id": "CSAFPID-5441264",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.2rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.2rc2",
                                "product": {
                                    "name": "vers:unknown/3.1.2rc2",
                                    "product_id": "CSAFPID-5441265",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.2rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.3",
                                "product": {
                                    "name": "vers:unknown/3.1.3",
                                    "product_id": "CSAFPID-5441266",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.3"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.3rc1",
                                "product": {
                                    "name": "vers:unknown/3.1.3rc1",
                                    "product_id": "CSAFPID-5441267",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.3rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.4",
                                "product": {
                                    "name": "vers:unknown/3.1.4",
                                    "product_id": "CSAFPID-5441268",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.4rc1",
                                "product": {
                                    "name": "vers:unknown/3.1.4rc1",
                                    "product_id": "CSAFPID-5441269",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.4rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.4rc2",
                                "product": {
                                    "name": "vers:unknown/3.1.4rc2",
                                    "product_id": "CSAFPID-5441270",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.4rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.5",
                                "product": {
                                    "name": "vers:unknown/3.1.5",
                                    "product_id": "CSAFPID-5441271",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.5rc1",
                                "product": {
                                    "name": "vers:unknown/3.1.5rc1",
                                    "product_id": "CSAFPID-5441272",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.5rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.6",
                                "product": {
                                    "name": "vers:unknown/3.1.6",
                                    "product_id": "CSAFPID-5597413",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.6rc1",
                                "product": {
                                    "name": "vers:unknown/3.1.6rc1",
                                    "product_id": "CSAFPID-5441273",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.6rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.7",
                                "product": {
                                    "name": "vers:unknown/3.1.7",
                                    "product_id": "CSAFPID-5597417",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.7rc1",
                                "product": {
                                    "name": "vers:unknown/3.1.7rc1",
                                    "product_id": "CSAFPID-5597414",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.7rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.7rc2",
                                "product": {
                                    "name": "vers:unknown/3.1.7rc2",
                                    "product_id": "CSAFPID-5597415",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.7rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.8rc1",
                                "product": {
                                    "name": "vers:unknown/3.1.8rc1",
                                    "product_id": "CSAFPID-5844841",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.8rc1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1.8rc2",
                                "product": {
                                    "name": "vers:unknown/3.1.8rc2",
                                    "product_id": "CSAFPID-5844842",
                                    "product_identification_helper": {
                                        "purl": "pkg:pypi/apache-airflow@3.1.8rc2"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=3.0.0|<3.1.8",
                                "product": {
                                    "name": "vers:unknown/>=3.0.0|<3.1.8",
                                    "product_id": "CSAFPID-5844843"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "apache-airflow"
                    }
                ],
                "category": "vendor",
                "name": "apache"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-28779",
            "notes": [
                {
                    "category": "description",
                    "text": "Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url.\nThis allows any application co-hosted under the same domain to capture valid Airflow session tokens from HTTP request headers, allowing full session takeover without attacking Airflow itself.\n\nUsers are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-28779"
                },
                {
                    "category": "description",
                    "text": "Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url.\nThis allows any application co-hosted under the same domain to capture valid Airflow session tokens from HTTP request headers, allowing full session takeover without attacking Airflow itself.\n\nUsers are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-28779"
                },
                {
                    "category": "description",
                    "text": "Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url.\nThis allows any application co-hosted under the same domain to capture valid Airflow session tokens from HTTP request headers, allowing full session takeover without attacking Airflow itself.\n\nUsers are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.",
                    "title": "github - https://github.com/advisories/GHSA-4fhm-p86v-hwpx"
                },
                {
                    "category": "description",
                    "text": "Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url.\nThis allows any application co-hosted under the same domain to capture valid Airflow session tokens from HTTP request headers, allowing full session takeover without attacking Airflow itself.\n\nUsers are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-airflow-2026-28779.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url.\nThis allows any application co-hosted under the same domain to capture valid Airflow session tokens from HTTP request headers, allowing full session takeover without attacking Airflow itself.\n\nUsers are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/PyPI%2FGHSA-4fhm-p86v-hwpx.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url.\nThis allows any application co-hosted under the same domain to capture valid Airflow session tokens from HTTP request headers, allowing full session takeover without attacking Airflow itself.\n\nUsers are recommended to upgrade to Apache Airflow 3.1.8 or later, which resolves this issue.",
                    "title": "github - https://api.github.com/advisories/GHSA-4fhm-p86v-hwpx"
                },
                {
                    "category": "other",
                    "text": "0.00069",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "4.7",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Certbundde",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "Is related to a product by vendor Apache, The value of the most recent EPSS score, Is related to (a version of) an uncommon product, There is cwe data available from source Github",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5831862",
                    "CSAFPID-5834228",
                    "CSAFPID-5838004",
                    "CSAFPID-5844740",
                    "CSAFPID-5441223",
                    "CSAFPID-5441233",
                    "CSAFPID-5441234",
                    "CSAFPID-5441235",
                    "CSAFPID-5441236",
                    "CSAFPID-5441237",
                    "CSAFPID-5441238",
                    "CSAFPID-5441239",
                    "CSAFPID-5441240",
                    "CSAFPID-5441241",
                    "CSAFPID-5441242",
                    "CSAFPID-5441243",
                    "CSAFPID-5441244",
                    "CSAFPID-5441245",
                    "CSAFPID-5441246",
                    "CSAFPID-5441247",
                    "CSAFPID-5441248",
                    "CSAFPID-5441249",
                    "CSAFPID-5441250",
                    "CSAFPID-5441251",
                    "CSAFPID-5441252",
                    "CSAFPID-5441253",
                    "CSAFPID-5441254",
                    "CSAFPID-5441255",
                    "CSAFPID-5441256",
                    "CSAFPID-5441257",
                    "CSAFPID-5441258",
                    "CSAFPID-5441259",
                    "CSAFPID-5441260",
                    "CSAFPID-5441261",
                    "CSAFPID-5441262",
                    "CSAFPID-5441263",
                    "CSAFPID-5441264",
                    "CSAFPID-5441265",
                    "CSAFPID-5441266",
                    "CSAFPID-5441267",
                    "CSAFPID-5441268",
                    "CSAFPID-5441269",
                    "CSAFPID-5441270",
                    "CSAFPID-5441271",
                    "CSAFPID-5441272",
                    "CSAFPID-5441273",
                    "CSAFPID-5597413",
                    "CSAFPID-5597414",
                    "CSAFPID-5597415",
                    "CSAFPID-5597417",
                    "CSAFPID-5844841",
                    "CSAFPID-5844842",
                    "CSAFPID-5844843"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-28779"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/28xxx/CVE-2026-28779.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28779"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-28779"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0755.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-28779"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://github.com/advisories/GHSA-4fhm-p86v-hwpx"
                },
                {
                    "category": "external",
                    "summary": "Source raw - github",
                    "url": "https://api.github.com/advisories/GHSA-4fhm-p86v-hwpx"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-airflow-2026-28779.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/PyPI%2FGHSA-4fhm-p86v-hwpx.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-4fhm-p86v-hwpx"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "https://github.com/apache/airflow/pull/62771"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; cveprojectv5; github; nvd; osv",
                    "url": "https://lists.apache.org/thread/r4n5znb8mcq14wo9v8ndml36nxlksdqb"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-0755.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-0755"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.apache.org/thread/g5o6khx83jwqvdyn0mlyb0krt35cs9ss"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.apache.org/thread/dwzf62qg9z8wvfsjknpfd8bvtwghd49s"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.apache.org/thread/1rs2v7fcko2otl6n9ytthcj87cmsgx51"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-26929"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-28563"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-28779"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-30911"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv",
                    "url": "http://www.openwall.com/lists/oss-security/2026/03/17/3"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28779"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-4fhm-p86v-hwpx"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-5441223",
                        "CSAFPID-5441233",
                        "CSAFPID-5441234",
                        "CSAFPID-5441235",
                        "CSAFPID-5441236",
                        "CSAFPID-5441237",
                        "CSAFPID-5441238",
                        "CSAFPID-5441239",
                        "CSAFPID-5441240",
                        "CSAFPID-5441241",
                        "CSAFPID-5441242",
                        "CSAFPID-5441243",
                        "CSAFPID-5441244",
                        "CSAFPID-5441245",
                        "CSAFPID-5441246",
                        "CSAFPID-5441247",
                        "CSAFPID-5441248",
                        "CSAFPID-5441249",
                        "CSAFPID-5441250",
                        "CSAFPID-5441251",
                        "CSAFPID-5441252",
                        "CSAFPID-5441253",
                        "CSAFPID-5441254",
                        "CSAFPID-5441255",
                        "CSAFPID-5441256",
                        "CSAFPID-5441257",
                        "CSAFPID-5441258",
                        "CSAFPID-5441259",
                        "CSAFPID-5441260",
                        "CSAFPID-5441261",
                        "CSAFPID-5441262",
                        "CSAFPID-5441263",
                        "CSAFPID-5441264",
                        "CSAFPID-5441265",
                        "CSAFPID-5441266",
                        "CSAFPID-5441267",
                        "CSAFPID-5441268",
                        "CSAFPID-5441269",
                        "CSAFPID-5441270",
                        "CSAFPID-5441271",
                        "CSAFPID-5441272",
                        "CSAFPID-5441273",
                        "CSAFPID-5597413",
                        "CSAFPID-5597414",
                        "CSAFPID-5597415",
                        "CSAFPID-5597417",
                        "CSAFPID-5831862",
                        "CSAFPID-5834228",
                        "CSAFPID-5838004",
                        "CSAFPID-5844740",
                        "CSAFPID-5844841",
                        "CSAFPID-5844842",
                        "CSAFPID-5844843"
                    ]
                }
            ],
            "title": "CVE-2026-28779"
        }
    ]
}