CVE-2026-30912

HIGH

Apache Airflow: Exposing stack trace in case of constraint error

Title source: cna
STIX 2.1

Description

In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.

Scores

CVSS v3 7.5
EPSS 0.0008
EPSS Percentile 23.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-668
Status published
Products (3)
apache/airflow < 3.2.0
Apache Software Foundation/Apache Airflow < 3.2.0
pypi/apache-airflow-core 0 - 3.2.0PyPI
Published Apr 18, 2026
Tracked Since Apr 18, 2026