
Apache Airflow CVE-2026-31987: JWT token appearing in logs https://www.openwall.com/lists/oss-security/2026/04/16/7 CVE-2026-30912: Exposing stack trace in case of constraint error https://www.openwall.com/lists/oss-security/2026/04/17/5 CVE-2026-32690: Nested Variable Secret Values Bypass Redaction via max_depth=1 https://www.openwall.com/lists/oss-security/2026/04/17/6
Post summary
The post enumerates three Apache Airflow CVEs with concise technical descriptions, but provides no proof of concepts, exploit code, patches, or evidence of active exploitation.



