CVE-2025-57735

CVE-2025-57735: Apache Airflow: Airflow Logout Not Invalidating JWT

Vendor Apache Software Foundation
Product Apache Airflow
Weakness CWE-613 · Insufficient session expiration
Published April 9, 2026
Last update April 9, 2026

CVSS base score

What the vulnerability does

Description

When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+ Users are recommended to upgrade to version 3.2.0, which fixes this issue.

Key dates

Disclosure timeline

April 9, 2026 CVE published
April 9, 2026 Record updated