CVE-2026-27173
published 2026-05-19CVE-2026-27173: JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users…
PriorityP346high8.7CVSS 3.1
AVLACLPRLUINSCCHIHAL
EPSS
0.16%
5.2th percentile
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 3.2.2 | 3.2.2 |
| apache | apache-airflow-providers-cncf-kubernetes | < 10.17.0 | 10.17.0 |
| apache_software_foundation | apache_airflow | < 3.2.2 | 3.2.2 |
CVSS provenance
nvdv3.18.7HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
ghsa8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
ghsa·2026-06-01·CVSS 8.7
CVE-2026-49298 [HIGH] CWE-538 Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. `pods/get` in the Airflow namespace) could harvest the JWT from `kubectl describe pod` output and then call state-mutating Execution API endpoints — triggering Dag runs, clearing runs, reading or writing Variables / Connections / XComs — as if they were a running task. Affects deployments using the `KubernetesExecutor`. Users are advised to upgrade to `apache-airflow` 3.2.2 or later. This is the airflow-core ha
GHSA
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in t
ghsa_unreviewed·2026-06-01·CVSS 8.7
CVE-2026-49298 [HIGH] CWE-538 A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in t
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in the pod spec. An authenticated UI/API user with Kubernetes read-only access to the cluster (e.g. `pods/get` in the Airflow namespace) could harvest the JWT from `kubectl describe pod` output and then call state-mutating Execution API endpoints — triggering Dag runs, clearing runs, reading or writing Variables / Connections / XComs — as if they were a running task. Affects deployments using the `KubernetesExecutor`. Users are advised to upgrade to `apache-airflow` 3.2.2 or later. This is the airflow-core half of the same vulnerability addressed by [CVE-2026-27173](https://www.cve.org/CVERecord?i
GHSA
GHSA-524w-vq63-2xhf: JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods
ghsa_unreviewed·2026-05-19
CVE-2026-27173 [HIGH] CWE-538 GHSA-524w-vq63-2xhf: JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks.
VulDB
Apache Airflow CNCF Kubernetes Provider up to 10.16.x JWT Token file information disclosure (EUVD-2026-30977)
vuldb·2026-05-19·CVSS 8.7
CVE-2026-27173 [HIGH] Apache Airflow CNCF Kubernetes Provider up to 10.16.x JWT Token file information disclosure (EUVD-2026-30977)
A vulnerability was found in Apache Airflow CNCF Kubernetes Provider up to 10.16.x. It has been declared as problematic. This issue affects some unknown processing of the component JWT Token Handler. Executing a manipulation can lead to file and directory information exposure.
This vulnerability is registered as CVE-2026-27173. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
ghsa·2026-05-19
CVE-2026-27173 [HIGH] CWE-538 Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-19
Published