<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T22:47:17.829531+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-airflow-2025-57735</id>
    <title>BIT-airflow-2025-57735 — Apache Airflow: Airflow Logout Not Invalidating JWT</title>
    <updated>2026-10-06T22:47:17.833125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: airflow</p>
<p>When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+</p>
<p>Users are recommended to upgrade to version 3.2.0, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-airflow-2025-57735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-290286</id>
    <title>EUVD-2026-290286</title>
    <updated>2026-10-06T22:47:17.833180+00:00</updated>
    <content>EUVD-2026-290286</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-290286"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-57735</id>
    <title>fkie_cve-2025-57735</title>
    <updated>2026-10-06T22:47:17.833196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+</p>
<p>Users are recommended to upgrade to version 3.2.0, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-57735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c92r-g8j5-vhcx</id>
    <title>GHSA-c92r-g8j5-vhcx — Apache Airflow: JWT token still valid after logout</title>
    <updated>2026-10-06T22:47:17.833221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: apache-airflow</p>
<p>When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+</p>
<p>Users are recommended to upgrade to version 3.2.0, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c92r-g8j5-vhcx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-269</id>
    <title>PYSEC-2026-269 — Apache Airflow: JWT token still valid after logout</title>
    <updated>2026-10-06T22:47:17.833242+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: apache-airflow</p>
<p>When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+</p>
<p>Users are recommended to upgrade to version 3.2.0, which fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-269"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1042</id>
    <title>WID-SEC-W-2026-1042 — Apache Airflow: Mehrere Schwachstellen</title>
    <updated>2026-10-06T22:47:17.833261+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Apache Airflow ausnutzen, um Sicherheitsvorkehrungen zu umgehen und vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1042"/>
  </entry>
</feed>
