Junglewise Threat Intelligence

CVE-2025-57735: Apache Airflow insufficient session expiration in JWT logout

CVE-2025-57735 · Severity: critical · CVSS 9.1 · Published 2026-04-09

Technologies: apache-airflow (PyPI), Apache Airflow. Vendors: PyPI, Apache.

Executive brief

Apache Airflow, a platform used to programmatically author and monitor workflows, contained a flaw where user session tokens remained valid even after a user logged out. If an attacker intercepted one of these tokens, they could continue to access the system as that user indefinitely until the token naturally expired. This could lead to unauthorized access to sensitive workflow data or the ability to trigger administrative actions.

Technical details

An insufficient session expiration vulnerability (CWE-613) exists in Apache Airflow versions 3.0.0 through 3.1.x. The application fails to revoke or blacklist JWT tokens when a user explicitly logs out, meaning the backend continues to accept the token as valid until its original expiration timestamp is reached. An attacker who obtains a valid JWT (e.g., through network interception or local access) can maintain authenticated access to the Airflow REST and UI APIs even after the legitimate user has terminated their session. The fix, introduced in version 3.2.0, implements a 'revoked_token' table to track and invalidate JTIs (JWT IDs) upon logout.

Affected products

  • Apache Airflow >= 3.0.0, < 3.2.0

Timeline

  • 2025-10-15: other: Initial backend JWT handling PR merged
  • 2026-02-05: other: Token revocation mechanism PR merged
  • 2026-04-09: advisory: Public disclosure of vulnerability
  • 2026-04-09: patched: Version 3.2.0 released

References

Related threats