
CVE-2026-27173: Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line https://www.openwall.com/lists/oss-security/2026/05/19/35 CVE-2026-42526: Apache Airflow Amazon provider: Unauthorized access in AWS Secrets Manager & SSM Parameter Store backends https://www.openwall.com/lists/oss-security/2026/05/19/36
Post summary
The text announces two new CVE disclosures for Apache Airflow providers, providing concise technical descriptions but lacking PoC, exploit code, patch information, or evidence of active exploitation.



