Severity: Moderate 

Affected versions:

- Apache Airflow (apache-airflow) 3.0.0 before 3.2.0

Description:

JWT Tokens used by tasks were exposed in logs. This could allow UI users to act 
as Dag Authors. 
Users are advised to upgrade to Airflow version that contains fix.

Users are recommended to upgrade to version 3.2.0, which fixes this issue.

Credit:

unixengineer (finder)
Jason Imison (finder)
Pineapple (remediation developer)

References:

https://github.com/apache/airflow/pull/62964
https://github.com/apache/airflow/issues/62428
https://github.com/apache/airflow/issues/62773
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-31987

Reply via email to