In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's /confirm endpoint.
/confirm
"https://github.com/pypa/advisory-database/blob/main/vulns/apache-airflow/PYSEC-2022-280.yaml"