Security Advisory

CVE-2025-57735

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-04-09 11:12:41
Last updated 2026-04-09 17:25:08
Assigner apache
CVSS score not scored
State PUBLISHED

Description

When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+ Users are recommended to upgrade to version 3.2.0, which fixes this issue.