CVE-2026-30912
published 2026-04-18CVE-2026-30912: In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.45%
36.2th percentile
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 3.2.0 | 3.2.0 |
| apache_software_foundation | apache_airflow | < 3.2.0 | 3.2.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w7cf-2pmc-5m4c: In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false
ghsa_unreviewed·2026-04-18
CVE-2026-30912 CWE-668 GHSA-w7cf-2pmc-5m4c: In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.
GHSA
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
ghsa·2026-04-18
CVE-2026-30912 [MEDIUM] CWE-668 Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.
VulDB
Apache Airflow up to 3.1.x information exposure
vuldb·2026-04-17
CVE-2026-30912 [LOW] Apache Airflow up to 3.1.x information exposure
A vulnerability marked as problematic has been reported in Apache Airflow up to 3.1.x. Affected by this vulnerability is an unknown functionality. The manipulation leads to information exposure through error message.
This vulnerability is documented as CVE-2026-30912. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-18
Published