GPU VulnDB

Database/Control plane, storage & DevOps

Apache Airflow: Core API logout does not revoke bearer tokens, so a stolen token outlives the session

CVSS 9.1CVE-2026-86473Control plane, storage & DevOpscurated

Impact

The Core API logout endpoint revokes only a session token presented in the _token cookie. A client that authenticates with an Authorization bearer header gets the normal logout response while nothing is revoked, and the token stays valid until it expires - 24 hours by default, configurable. An attacker who already holds a copy of a user's token keeps that user's access after the victim has logged out and believes the session is over, which removes logout as an incident-response lever on a scheduler that orchestrates training and data pipelines. The attacker gains no privileges beyond the victim's own, and how the token was obtained is outside this issue.

Who can reach it

Network access to the Airflow Core API, holding a previously captured valid bearer token. Affects API clients that authenticate with bearer tokens rather than the browser session cookie.

What to do

Upgrade apache-airflow to 3.3.2 or later and restart the API server/webserver - a control-plane service restart, no worker or GPU node disruption. Until then, shorten the configured token lifetime and rotate the signing key if you need to invalidate outstanding tokens, since logout will not do it.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.