CVE-2026-31987
published 2026-04-16CVE-2026-31987: JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.74%
50.7th percentile
JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors.
Users are advised to upgrade to Airflow version that contains fix.
Users are recommended to upgrade to version 3.2.0, which fixes this issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | >= 3.0.0 < 3.2.0 | 3.2.0 |
| apache_software_foundation | apache_airflow | >= 3.0.0 < 3.2.0 | 3.2.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ghsa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Airflow: JWT token appearing in logs
ghsa·2026-04-16
CVE-2026-31987 [MEDIUM] CWE-532 Apache Airflow: JWT token appearing in logs
Apache Airflow: JWT token appearing in logs
JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors.
Users are advised to upgrade to Airflow version that contains fix.
Users are recommended to upgrade to version 3.2.0, which fixes this issue.
VulDB
Apache Airflow up to 3.1.x JWT Token log file (ID 62428)
vuldb·2026-04-16
CVE-2026-31987 [LOW] Apache Airflow up to 3.1.x JWT Token log file (ID 62428)
A vulnerability described as problematic has been identified in Apache Airflow up to 3.1.x. This issue affects some unknown processing of the component JWT Token Handler. Executing a manipulation can lead to sensitive information in log files.
This vulnerability is tracked as CVE-2026-31987. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-16
Published