CVE 9.1 CRITICAL

Apache Airflow: Airflow Logout Not Invalidating JWT_CVE-2025-57735

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+



Users are recommended to upgrade to version 3.2.0, which fixes this issue.

Basic Information

ID CVE-2025-57735
Source apache
Published Apr 9, 2026 at 11:12
Modified Apr 9, 2026 at 17:25

Affected Product

Vendor Apache Software Foundation
Product Apache Airflow
Version 3.0.0
Affected Versions Apache Software Foundation Apache Airflow 3.0.0

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.