Insertion of Sensitive Information into Externally-Accessible File or Directory Affecting apache-airflow-core package, versions [,3.2.2rc1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.49% (39th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWCORE-17895111
  • published8 Jul 2026
  • disclosed1 Jun 2026
  • creditNikolai Dvoinishnikov, Anton Kuznetsov

Introduced: 1 Jun 2026

CVE-2026-49298  (opens in a new tab)
CWE-538  (opens in a new tab)

How to fix?

Upgrade apache-airflow-core to version 3.2.2rc1 or higher.

Overview

Affected versions of this package are vulnerable to Insertion of Sensitive Information into Externally-Accessible File or Directory in the KubernetesExecutor process. An attacker can gain unauthorized access to sensitive API endpoints by harvesting JWT tokens from command-line arguments exposed in pod specifications. This allows the attacker to perform actions such as triggering DAG runs, clearing runs, and reading or modifying Variables, Connections, or XComs by leveraging Kubernetes read-only access to retrieve the JWT from pod metadata.

CVSS Base Scores

version 4.0
version 3.1