PT-2026-33314 · Apache · Apache Airflow

·

CVE-2026-31987

·

Published

2026-04-16

·

Updated

2026-07-13

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 3.2.0
Description JWT Tokens used by tasks were exposed in logs. This exposure could allow UI users to act as Dag Authors.
Recommendations Upgrade to version 3.2.0.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2026-31987
CVE-2026-31987
ECHO-84A5-62F5-0D42
GHSA-PHV5-VQ5P-QHP7
PYSEC-2026-2352

Affected Products

Apache Airflow