PT-2026-33314 · Apache · Apache Airflow

Jason Imison

+2

·

Published

2026-04-16

·

Updated

2026-04-19

·

CVE-2026-31987

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 3.2.0
Description JWT Tokens used by tasks were exposed in logs. This exposure could allow UI users to act as Dag Authors.
Recommendations Upgrade to version 3.2.0.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2026-31987
CVE-2026-31987
GHSA-PHV5-VQ5P-QHP7

Affected Products

Apache Airflow