HarborGuard / CVE
Back to search
HIGHCVE-2026-31987Published Modified CNA apache

CVE-2026-31987: Apache Airflow: JWT token appearing in logs

JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue.

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
3.2.0
Affected Products
1

Fix available

3.2.0
Patch commits
Affected packages
  • Apache Software Foundation / Apache Airflow
    < 3.2.0 (from 3.0.0)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N