
CVE-2026-27173: Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line https://www.openwall.com/lists/oss-security/2026/05/19/35 CVE-2026-42526: Apache Airflow Amazon provider: Unauthorized access in AWS Secrets Manager & SSM Parameter Store backends https://www.openwall.com/lists/oss-security/2026/05/19/36
Post summary
The post announces two newly disclosed Apache Airflow CVEs: one that exposes JWT tokens in the KubernetesExecutor command line and another that permits unauthorized access to AWS Secrets Manager and SSM Parameter Store backends.


