Database/Control plane, storage & DevOps
Apache Airflow: logout does not invalidate the session JWT, so an intercepted token stays usable
Impact
Airflow before 3.2.0 never invalidates the JWT a user authenticated with when that user logs out, so a token captured from a browser, a proxy log or a shared workstation keeps working until it expires on its own. Where Airflow drives the fleet - submitting training jobs, staging datasets, triggering model builds - a replayed token means DAG trigger and edit rights, and in most deployments the ability to run code on workers through a new or modified DAG. The exposure is conditional on the token being obtained in the first place; this is a session-lifetime weakness, not a remote code execution bug, despite the 9.1 score the project assigned.
Who can reach it
Anyone who can obtain a valid Airflow JWT - network interception, a logged proxy, a shared or recycled browser session - and reach the Airflow API server. No credentials needed beyond the stolen token; logging out does not revoke it.
What to do
Upgrade to Airflow 3.2.0 or later, which implements token invalidation at logout, and restart the API server and schedulers. No node drain. On older versions the only mitigations are shortening the JWT lifetime, rotating the signing secret to force-expire outstanding tokens, and keeping the web UI behind TLS and an authenticating proxy.
References
Related entries
- HashiCorp Vault: Root-namespace operator with write on sys/audit gains code execution on the Vault hostCVE-2025-6000 · HashiCorp VaultCritical
- Lantronix EDS3000PS serial-to-Ethernet device server: Full bypass of the management-page loginCVE-2025-67039 · Lantronix EDS3000PS serial-to-Ethernet device serverCritical
- Palo Alto PAN-OS: GlobalProtect portal/gateway auth bypassCVE-2026-0257 · Palo Alto PAN-OSCritical
- Grafana MCP Server: caller-controlled X-Grafana-URL header turns grafana_api_request into a full SSRF primitiveCVE-2026-19516 · mcp-grafana (Grafana MCP Server, X-Grafana-URL destination control)Critical
- Apache CloudStack Proxmox extension (cross-tenant instance access): The extension keys CloudStack instances to ProxmoxCVE-2026-25199 · Apache CloudStack Proxmox extension (cross-tenant instance access)Critical
- BACnet Stack open-source C library (bacnet-stack) embedded in third-party controllers and gateways: A runCVE-2026-41475 · BACnet Stack open-source C library (bacnet-stack) embedded in third-party controllers and gatewaysCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.