CVE-2026-31987

CVE-2026-31987: Apache Airflow: JWT token appearing in logs

Vendor Apache Software Foundation
Product Apache Airflow
Weakness CWE-532 · Sensitive info in logs
Published April 16, 2026
Last update April 18, 2026

CVSS base score

What the vulnerability does

Description

JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue.

Key dates

Disclosure timeline

April 16, 2026 CVE published
April 18, 2026 Record updated