https://seclists.org/oss-sec/2026/q2/754: CVE-2026-49298: Apache Airflow: JWT Token Exposuin KubernetesExecutor Command-Line Arguments
Published May 31, 2026
·Updated
Affected Software
1 affected component
pypi/apache-airflow<3.2.2
Frequently Asked Questions
1
What is the severity of CVE-2026-49298?
The severity of CVE-2026-49298 is classified as moderate.
2
Which versions of Apache Airflow are affected by CVE-2026-49298?
CVE-2026-49298 affects Apache Airflow versions prior to 3.2.2.
3
What is the nature of the vulnerability in CVE-2026-49298?
CVE-2026-49298 is related to JWT token exposure in command-line arguments of the KubernetesExecutor.
4
How do I fix CVE-2026-49298?
To mitigate CVE-2026-49298, upgrade to Apache Airflow version 3.2.2 or later.
5
What are the implications of CVE-2026-49298 for KubernetesExecutor users?
Users of KubernetesExecutor in Apache Airflow should be aware that JWT tokens may be exposed in command-line arguments, potentially leading to unauthorized access.