CVE-2026-31987Disclosure(apache / airflow)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache airflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-17); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-16: 1Mentions · 2026-04-17: 2Mentions · 2026-04-19: 1Patch / Workaround · 2026-04-17: 2Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 2Technical Details · 2026-04-19: 104-1604-1704-19
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-161
Disclosure1
2026-04-172
Patch2
2026-04-191
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31987 JWT Token Exposure in Apache Airflow Logs Enabling Unauth... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31987 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces a disclosed vulnerability (CVE‑2026‑31987) detailing JWT token exposure in Apache Airflow logs, but offers no PoC, exploit, or mitigation information.

    0001183
    4.0K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Airflow CVE-2026-31987: JWT token appearing in logs https://www.openwall.com/lists/oss-security/2026/04/16/7 CVE-2026-30912: Exposing stack trace in case of constraint error https://www.openwall.com/lists/oss-security/2026/04/17/5 CVE-2026-32690: Nested Variable Secret Values Bypass Redaction via max_depth=1 https://www.openwall.com/lists/oss-security/2026/04/17/6

    Post summary

    The message announces three new Apache Airflow CVEs with concise descriptions, but provides no evidence of exploitation, patches, or PoC references.

    1000066
    4.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-31987 JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. U… https://www.cve.org/CVERecord?id=CVE-2026-31987 ----- Traducción: CVE-2026-31987: Lo… http://infoflow.cloud`

    Post summary

    CVE-2026-31987 allows UI users to act as Dag authors by exposing JWT tokens in logs; users are advised to upgrade Airflow to a patch version.

    0000025
    71 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31987 JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. U… https://www.cve.org/CVERecord?id=CVE-2026-31987

    Post summary

    The advisory warns that JWT tokens are exposed in logs, allowing UI users to act as Dag Authors, and recommends upgrading to a patched Airflow version.

    00000102
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more