Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-524w-vq63-2xhf | Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments |
Wed, 20 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow Cncf Kubernetes |
|
| Vendors & Products |
Apache
Apache airflow Cncf Kubernetes |
Tue, 19 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 19 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 19 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks. | |
| Title | Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments | |
| Weaknesses | CWE-538 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-05-19T19:57:11.716Z
Reserved: 2026-02-18T14:18:43.403Z
Link: CVE-2026-27173
Updated: 2026-05-19T19:34:01.489Z
Status : Awaiting Analysis
Published: 2026-05-19T20:16:17.440
Modified: 2026-06-17T10:26:47.637
Link: CVE-2026-27173
No data.
OpenCVE Enrichment
Updated: 2026-05-20T10:15:15Z
Github GHSA