Apache AirflowPYSEC-2026-18
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.
High7.5CVE-2026-30912 · Published Apr 18, 2026 · updated Jul 13, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 3.2.0 | 3.2.0 |
Details and references
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the CVSS score
- Also known as
- BIT-airflow-2026-30912, CVE-2026-30912, GHSA-w7cf-2pmc-5m4c, PYSEC-2026-2361
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 18 | Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. CVE-2026-25917High7.2fixed in 3.2.0 | High7.2 | 3.2.0 |
| Apr 18 | Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries CVE-2026-32690Low3.7fixed in 3.2.0 | Low3.7 | 3.2.0 |
| Apr 16 | Apache Airflow: JWT token appearing in logs CVE-2026-31987Medium7.5fixed in 3.2.0 | Medium7.5 | 3.2.0 |
| Apr 16 | Apache Airflow: RCE by race condition in example_xcom dag CVE-2025-54550High8.1fixed in 3.2.0 | High8.1 | 3.2.0 |
| Apr 15 | Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access CVE-2026-25219Medium6.5fixed in 3.1.8 | Medium6.5 | 3.1.8 |
| Apr 13 | Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API CVE-2026-33858High8.8fixed in 3.2.0 | High8.8 | 3.2.0 |