{"id":"PYSEC-2026-2365","summary":"Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments","details":"JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks.","aliases":["CVE-2026-27173","GHSA-524w-vq63-2xhf"],"modified":"2026-07-13T16:49:08.228378643Z","published":"2026-07-13T15:19:09.381998Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27173"},{"type":"WEB","url":"https://github.com/apache/airflow/pull/60108"},{"type":"PACKAGE","url":"https://github.com/apache/airflow"},{"type":"WEB","url":"https://lists.apache.org/thread/pk3m2z4s2rkmc0v6gh9hnch9spc6stqw"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/05/19/35"},{"type":"PACKAGE","url":"https://pypi.org/project/apache-airflow-providers-cncf-kubernetes"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-524w-vq63-2xhf"}],"affected":[{"package":{"name":"apache-airflow-providers-cncf-kubernetes","ecosystem":"PyPI","purl":"pkg:pypi/apache-airflow-providers-cncf-kubernetes"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.17.0"}]}],"versions":["1.0.0","1.0.0b1","1.0.0b2","1.0.0rc1","1.0.1","1.0.1rc1","1.0.2","1.0.2rc1","1.1.0","1.1.0rc1","1.2.0","1.2.0rc1","10.0.0","10.0.0rc1","10.0.1","10.0.1rc1","10.1.0","10.1.0rc1","10.1.0rc2","10.10.0","10.10.0rc1","10.11.0","10.11.0rc1","10.11.0rc2","10.11.1","10.11.1rc1","10.12.0","10.12.0rc1","10.12.1","10.12.1rc1","10.12.2","10.12.2rc2","10.12.3","10.12.3rc1","10.12.4","10.12.4rc1","10.13.0","10.13.0rc1","10.14.0","10.14.0rc1","10.15.0","10.15.0rc1","10.16.0","10.16.0rc1","10.16.1","10.16.1rc1","10.17.0rc1","10.2.0","10.3.0","10.3.0rc1","10.3.1","10.3.1rc1","10.4.0","10.4.0b1","10.4.0rc1","10.4.1","10.4.1rc1","10.4.2","10.4.2rc1","10.4.3","10.4.3rc1","10.5.0","10.5.0rc1","10.5.0rc2","10.6.0","10.6.0rc1","10.6.1","10.6.1rc1","10.6.2","10.6.2rc1","10.7.0","10.7.0rc1","10.8.0","10.8.0rc1","10.8.1","10.8.1rc1","10.8.2","10.8.2rc1","10.9.0","10.9.0rc1","2.0.0","2.0.0rc1","2.0.0rc2","2.0.1","2.0.1rc1","2.0.1rc2","2.0.2","2.0.2rc1","2.0.3","2.0.3rc1","2.1.0","2.1.0rc1","2.2.0","2.2.0rc1","3.0.0","3.0.0rc1","3.0.1","3.0.1rc1","3.0.2","3.0.2rc1","3.0.2rc2","3.1.0","3.1.0rc1","3.1.1","3.1.1rc1","3.1.2","3.1.2rc1","4.0.0","4.0.0rc1","4.0.1","4.0.1rc1","4.0.2","4.0.2rc1","4.1.0","4.1.0rc2","4.2.0","4.2.0rc1","4.3.0","4.3.0rc1","4.3.0rc2","4.3.0rc3","4.4.0","4.4.0rc1","5.0.0","5.0.0rc3","5.1.0","5.1.0rc1","5.1.0rc2","5.1.1","5.1.1rc1","5.2.0","5.2.0rc1","5.2.1","5.2.1rc1","5.2.2","5.2.2rc1","5.3.0","5.3.0rc1","6.0.0","6.0.0rc1","6.1.0","6.1.0rc1","6.2.0rc1","7.0.0","7.0.0rc2","7.1.0","7.1.0rc1","7.10.0","7.10.0rc1","7.11.0","7.11.0rc1","7.12.0","7.12.0rc1","7.13.0","7.13.0rc1","7.14.0","7.14.0rc1","7.14.0rc2","7.2.0","7.2.0rc1","7.2.0rc2","7.3.0","7.3.0rc1","7.4.0","7.4.0rc1","7.4.1","7.4.1rc1","7.4.2","7.4.2rc1","7.5.0","7.5.0rc1","7.5.0rc2","7.5.1","7.5.1rc1","7.6.0","7.6.0rc1","7.7.0","7.7.0rc1","7.8.0","7.8.0rc1","7.9.0","7.9.0rc1","8.0.0","8.0.0rc1","8.0.0rc2","8.0.0rc3","8.0.1","8.0.1rc1","8.1.0","8.1.0rc1","8.1.1","8.1.1rc1","8.2.0","8.2.0rc1","8.3.0","8.3.0rc1","8.3.0rc2","8.3.1","8.3.1rc1","8.3.2","8.3.2rc1","8.3.3","8.3.3rc1","8.3.4","8.3.4rc1","8.4.0","8.4.0rc1","8.4.1","8.4.1rc1","8.4.2","8.4.2rc1","9.0.0","9.0.0rc1","9.0.1","9.0.1rc1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/apache-airflow-providers-cncf-kubernetes/PYSEC-2026-2365.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"}]}