CVE-2025-57735

CRITICAL

Apache Airflow: Airflow Logout Not Invalidating JWT

Title source: cna
STIX 2.1

Description

When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+ Users are recommended to upgrade to version 3.2.0, which fixes this issue.

Scores

CVSS v3 9.1
EPSS 0.0004
EPSS Percentile 10.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (3)
apache/airflow 3.0.0 - 3.2.0
Apache Software Foundation/Apache Airflow 3.0.0 - 3.2.0
pypi/apache-airflow 3.0.0 - 3.2.0PyPI
Published Apr 09, 2026
Tracked Since Apr 09, 2026