<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 23:50:48 +0000</lastBuildDate>
    <item>
      <title>BIT-airflow-2025-57735 — Apache Airflow: Airflow Logout Not Invalidating JWT</title>
      <link>https://cve.radiocsirt.org/vuln/bit-airflow-2025-57735</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: airflow&lt;/p&gt;
&lt;p&gt;When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.2.0, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: airflow&lt;/p&gt;
&lt;p&gt;When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.2.0, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-airflow-2025-57735</guid>
    </item>
    <item>
      <title>EUVD-2026-290286</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290286</link>
      <description>EUVD-2026-290286</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290286</guid>
    </item>
    <item>
      <title>fkie_cve-2025-57735</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-57735</link>
      <description>&lt;p&gt;When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.2.0, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.2.0, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-57735</guid>
    </item>
    <item>
      <title>GHSA-c92r-g8j5-vhcx — Apache Airflow: JWT token still valid after logout</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c92r-g8j5-vhcx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: apache-airflow&lt;/p&gt;
&lt;p&gt;When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.2.0, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: apache-airflow&lt;/p&gt;
&lt;p&gt;When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.2.0, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c92r-g8j5-vhcx</guid>
    </item>
    <item>
      <title>PYSEC-2026-269 — Apache Airflow: JWT token still valid after logout</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-269</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: apache-airflow&lt;/p&gt;
&lt;p&gt;When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.2.0, which fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: apache-airflow&lt;/p&gt;
&lt;p&gt;When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of that token in case it was intercepted. In Airflow 3.2 we implemented the mechanism that implements token invalidation at logout. Users who are concerned about the logout scenario and possibility of intercepting the tokens, should upgrade to Airflow 3.2+&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 3.2.0, which fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-269</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1042 — Apache Airflow: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1042</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache Airflow ausnutzen, um Sicherheitsvorkehrungen zu umgehen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Apache Airflow ausnutzen, um Sicherheitsvorkehrungen zu umgehen und vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1042</guid>
    </item>
  </channel>
</rss>
