Inclusion of Sensitive Information in Log Files in Apache Airflow - CVE-2026-31987
Published: August 25, 2026
Vulnerability identifier: #VU145324
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31987
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to impersonate Dag Authors.
The vulnerability exists due to exposure of sensitive information in task logs when logging JWT tokens used by tasks. A remote user can read exposed tokens from logs to impersonate Dag Authors.
Only UI users with access to the affected logs can exploit this issue.
Affected software
Apache Airflow
How to mitigate CVE-2026-31987
Install security update from vendor's website.
Apache Airflow - update to 3.2.0