Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <dfb8ec95-d826-45a1-f879-8b619e3425b1@apache.org>
Date: Thu, 16 Apr 2026 13:30:05 +0000
From: Rahul Vats <rahulvats@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2026-31987: Apache Airflow: JWT token appearing in logs 

Severity: Moderate 

Affected versions:

- Apache Airflow (apache-airflow) 3.0.0 before 3.2.0

Description:

JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. 
Users are advised to upgrade to Airflow version that contains fix.

Users are recommended to upgrade to version 3.2.0, which fixes this issue.

Credit:

unixengineer (finder)
Jason Imison (finder)
Pineapple (remediation developer)

References:

https://github.com/apache/airflow/pull/62964
https://github.com/apache/airflow/issues/62428
https://github.com/apache/airflow/issues/62773
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-31987

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.