Description
JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue.
Problem types
CWE-532 Insertion of Sensitive Information into Log File
Product status
3.0.0 (semver) before 3.2.0
Credits
unixengineer
Jason Imison
Pineapple
References
www.openwall.com/lists/oss-security/2026/04/16/7
github.com/apache/airflow/pull/62964
github.com/apache/airflow/issues/62428
github.com/apache/airflow/issues/62773
lists.apache.org/thread/pvsrtxzwo9xy6xgknmwslv4zrw70kt6g