Executive brief
Apache Airflow, a platform used to programmatically author and monitor workflows, contained a flaw where user session tokens remained valid even after a user logged out. If an attacker intercepted one of these tokens, they could continue to access the system as that user indefinitely until the token naturally expired. This could lead to unauthorized access to sensitive workflow data or the ability to trigger administrative actions.
Technical details
An insufficient session expiration vulnerability (CWE-613) exists in Apache Airflow versions 3.0.0 through 3.1.x. The application fails to revoke or blacklist JWT tokens when a user explicitly logs out, meaning the backend continues to accept the token as valid until its original expiration timestamp is reached. An attacker who obtains a valid JWT (e.g., through network interception or local access) can maintain authenticated access to the Airflow REST and UI APIs even after the legitimate user has terminated their session. The fix, introduced in version 3.2.0, implements a 'revoked_token' table to track and invalidate JTIs (JWT IDs) upon logout.
Affected products
- Apache Airflow >= 3.0.0, < 3.2.0
Timeline
- 2025-10-15: other: Initial backend JWT handling PR merged
- 2026-02-05: other: Token revocation mechanism PR merged
- 2026-04-09: advisory: Public disclosure of vulnerability
- 2026-04-09: patched: Version 3.2.0 released