JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks.
{
"github_reviewed": true,
"github_reviewed_at": "2026-06-05T16:37:13Z",
"nvd_published_at": "2026-05-19T20:16:17Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-538"
]
}