Severity: low 

Affected versions:

- Apache Airflow (apache-airflow) 3.0.0 before 3.2.0

Description:

When user logged out, the JWT token the user had authtenticated with was not 
invalidated, which could lead to reuse of that token in case it was 
intercepted. In Airflow 3.2 we implemented the mechanism that implements token 
invalidation at logout. Users who are concerned about the logout scenario and 
possibility of intercepting the tokens, should upgrade to Airflow 3.2+



Users are recommended to upgrade to version 3.2.0, which fixes this issue.

Credit:

Saurabh Banawar (finder)
Anish Giri (remediation developer)
vincent beck (remediation developer)

References:

https://github.com/apache/airflow/pull/61339
https://github.com/apache/airflow/pull/56633
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2025-57735

Reply via email to