Inclusion of Sensitive Information in Log Files in Apache Airflow - CVE-2026-31987

 

Inclusion of Sensitive Information in Log Files in Apache Airflow - CVE-2026-31987

Published: August 25, 2026


Vulnerability identifier: #VU145324
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31987
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to impersonate Dag Authors.

The vulnerability exists due to exposure of sensitive information in task logs when logging JWT tokens used by tasks. A remote user can read exposed tokens from logs to impersonate Dag Authors.

Only UI users with access to the affected logs can exploit this issue.


Affected software

Apache Airflow

How to mitigate CVE-2026-31987

Install security update from vendor's website.

Apache Airflow - update to 3.2.0

External References

Related Security Bulletins