Apache AirflowGHSA-phv5-vq5p-qhp7
Apache Airflow: JWT token appearing in logs
Medium7.5CVE-2026-31987 · Published Apr 16, 2026 · updated Jul 13, 2026
JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | >= 3.0.0, < 3.2.0 | 3.2.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-532
- Also known as
- BIT-airflow-2026-31987, CVE-2026-31987, PYSEC-2026-2352
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 18 | Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries | Low3.7 | 3.2.0 |
| Apr 18 | In case of SQL errors | High7.5 | 3.2.0 |
| Apr 18 | Apache Airflow: code execution | High7.2 | 3.2.0 |
| Apr 16 | Apache Airflow: RCE by race condition in example_xcom dag | High8.1 | 3.2.0 |
| Apr 15 | Apache Airflow: information disclosure | Medium6.5 | 3.1.8 |
| Apr 13 | Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API | High8.8 | 3.2.0 |