7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors.
Users are advised to upgrade to Airflow version that contains fix.
Users are recommended to upgrade to version 3.2.0, which fixes this issue.
Users are advised to upgrade to Airflow version that contains fix.
Users are recommended to upgrade to version 3.2.0, which fixes this issue.
Basic Information
ID
CVE-2026-31987
Source
apache
Published
Apr 16, 2026 at 13:31
Modified
Apr 18, 2026 at 02:28
Affected Product
Vendor
Apache Software Foundation
Product
Apache Airflow
Version
3.0.0
Affected Versions
Apache Software Foundation Apache Airflow 3.0.0