CVE-2025-57735Disclosure(apache / airflow)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+ Users are recommended to upgrade to version 3.2.0, which fixes this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-09); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 2Mentions · 2026-04-12: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-10: 1Technical Details · 2026-04-12: 104-0904-1004-12
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure3
2026-04-102
Disclosure1General1
2026-04-121
Disclosure1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-34538: Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure) https://www.openwall.com/lists/oss-security/2026/04/09/9 CVE-2025-57735: Apache Airflow: Airflow Logout Not Invalidating JWT https://www.openwall.com/lists/oss-security/2026/04/09/16 Both are "Severity: low"

    Post summary

    Both CVEs, identified as low severity, are disclosed via an OpenWall mailing list with technical details but no PoC, exploit code, active exploitation reports, or patch information.

    01050737
    4.6K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Apache Airflow` instances are affected by CVE-2025-57735, where JWT tokens remain valid post-logout, enabling unauthorized access. Review #Airflow deployments for #AuthBypass risk. https://www.pulsepatch.io/posts/cve-2025-57735-apache-airflow-jwt-valid-after-logout

    Post summary

    CVE-2025-57735 exposes an auth bypass in Apache Airflow where JWT tokens stay valid after logout, creating a risk of unauthorized access.

    00000227
    13 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2025-57735 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-57735 #CVE-2025-57735 #CVE #CyberSecurity #InfoSec https://t.co/nzu9t1YO2j

    Post summary

    The tweet announces the existence of CVE-2025-57735 with minimal details, providing only a reference link to the NVD entry and no additional technical or mitigation information.

    00000293
    123 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-57735 When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airfl… https://www.cve.org/CVERecord?id=CVE-2025-57735 ----- Traducción: CVE-2025-57735 Cua… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2025‑57735, noting that JWT tokens remain valid after logout, potentially enabling token reuse.

    00000261
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-57735 When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airfl… https://www.cve.org/CVERecord?id=CVE-2025-57735

    Post summary

    The CVE-2025-57735 vulnerability describes a scenario where a JWT token remains valid after logout, permitting reuse if intercepted. No PoC, exploit, active use, or patch is mentioned.

    00000234
    57.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-57735 - Apache Airflow: Airflow Logout Not Invalidating JWT Intel Report: https://ift.tt/lcG6hnk

    Post summary

    The tweet discloses CVE‑2025‑57735, noting that Airflow logout fails to invalidate JWT tokens, without providing exploits, patches, or evidence of active exploitation.

    00000221
    280 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more