Insufficient Session Expiration Affecting apache-airflow-core package, versions [3.0.0rc1, 3.2.0b1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.67% (47th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWCORE-15954280
  • published9 Apr 2026
  • disclosed9 Apr 2026
  • creditSaurabh Banawar

Introduced: 9 Apr 2026

CVE-2025-57735  (opens in a new tab)
CWE-613  (opens in a new tab)

How to fix?

Upgrade apache-airflow-core to version 3.2.0b1 or higher.

Overview

Affected versions of this package are vulnerable to Insufficient Session Expiration through the logout handler in airflow-core/src/airflow/api_fastapi/core_api/routes/public/auth.py and the token validation path in airflow-core/src/airflow/api_fastapi/auth/managers/base_auth_manager.py. An attacker can continue using an intercepted session token after the user logs out by replaying the still-valid JWT. This lets the attacker continue to access the Airflow API as that user, exposing DAGs, variables, connections, and other authenticated functionality until the token expires.

CVSS Base Scores

version 4.0
version 3.1