CVE-2026-27173

CVE-2026-27173: Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments

Vendor Apache Software Foundation
Product Apache Airflow CNCF Kubernetes provider
Weakness CWE-538
Published May 19, 2026
Last update May 19, 2026

CVSS base score

What the vulnerability does

Description

JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks.

Key dates

Disclosure timeline

May 19, 2026 CVE published
May 19, 2026 Record updated