https://seclists.org/oss-sec/2026/q2/149: CVE-2026-31987: Apache Airflow: JWT token appearing in logs
Published Apr 16, 2026
·Updated
Affected Software
1 affected component
pypi/apache-airflow>=3.0.0<3.2.0
Frequently Asked Questions
1
What is the severity of CVE-2026-31987?
The severity of CVE-2026-31987 is classified as Moderate.
2
Which versions of Apache Airflow are affected by CVE-2026-31987?
CVE-2026-31987 affects Apache Airflow versions 3.0.0 before 3.2.0.
3
What is the main issue described in CVE-2026-31987?
CVE-2026-31987 describes the exposure of JWT tokens used by tasks in logs, potentially allowing UI users to impersonate Dag Authors.
4
How does CVE-2026-31987 affect users of Apache Airflow?
Users of Apache Airflow could be at risk of unauthorized access and actions being taken on their behalf due to exposed JWT tokens.
5
How do I fix CVE-2026-31987?
To fix CVE-2026-31987, users are advised to upgrade to Apache Airflow version 3.2.0 or later.