GHSA-524w-vq63-2xhf

Suggest an improvement
Source
https://github.com/advisories/GHSA-524w-vq63-2xhf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-524w-vq63-2xhf/GHSA-524w-vq63-2xhf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-524w-vq63-2xhf
Aliases
  • CVE-2026-27173
Downstream
Published
2026-05-19T21:32:03Z
Modified
2026-06-05T16:45:19.541595530Z
Severity
  • 8.7 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L CVSS Calculator
Summary
Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments
Details

JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks.

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2026-06-05T16:37:13Z",
    "nvd_published_at": "2026-05-19T20:16:17Z",
    "severity": "HIGH",
    "cwe_ids": [
        "CWE-538"
    ]
}
References

Affected packages

PyPI / apache-airflow-providers-cncf-kubernetes

Package

Name
apache-airflow-providers-cncf-kubernetes
View open source insights on deps.dev
Purl
pkg:pypi/apache-airflow-providers-cncf-kubernetes

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.17.0

Affected versions

1.*
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.0
1.0.1rc1
1.0.1
1.0.2rc1
1.0.2
1.1.0rc1
1.1.0
1.2.0rc1
1.2.0
2.*
2.0.0rc1
2.0.0rc2
2.0.0
2.0.1rc1
2.0.1rc2
2.0.1
2.0.2rc1
2.0.2
2.0.3rc1
2.0.3
2.1.0rc1
2.1.0
2.2.0rc1
2.2.0
3.*
3.0.0rc1
3.0.0
3.0.1rc1
3.0.1
3.0.2rc1
3.0.2rc2
3.0.2
3.1.0rc1
3.1.0
3.1.1rc1
3.1.1
3.1.2rc1
3.1.2
4.*
4.0.0rc1
4.0.0
4.0.1rc1
4.0.1
4.0.2rc1
4.0.2
4.1.0rc2
4.1.0
4.2.0rc1
4.2.0
4.3.0rc1
4.3.0rc2
4.3.0rc3
4.3.0
4.4.0rc1
4.4.0
5.*
5.0.0rc3
5.0.0
5.1.0rc1
5.1.0rc2
5.1.0
5.1.1rc1
5.1.1
5.2.0rc1
5.2.0
5.2.1rc1
5.2.1
5.2.2rc1
5.2.2
5.3.0rc1
5.3.0
6.*
6.0.0rc1
6.0.0
6.1.0rc1
6.1.0
6.2.0rc1
7.*
7.0.0rc2
7.0.0
7.1.0rc1
7.1.0
7.2.0rc1
7.2.0rc2
7.2.0
7.3.0rc1
7.3.0
7.4.0rc1
7.4.0
7.4.1rc1
7.4.1
7.4.2rc1
7.4.2
7.5.0rc1
7.5.0rc2
7.5.0
7.5.1rc1
7.5.1
7.6.0rc1
7.6.0
7.7.0rc1
7.7.0
7.8.0rc1
7.8.0
7.9.0rc1
7.9.0
7.10.0rc1
7.10.0
7.11.0rc1
7.11.0
7.12.0rc1
7.12.0
7.13.0rc1
7.13.0
7.14.0rc1
7.14.0rc2
7.14.0
8.*
8.0.0rc1
8.0.0rc2
8.0.0rc3
8.0.0
8.0.1rc1
8.0.1
8.1.0rc1
8.1.0
8.1.1rc1
8.1.1
8.2.0rc1
8.2.0
8.3.0rc1
8.3.0rc2
8.3.0
8.3.1rc1
8.3.1
8.3.2rc1
8.3.2
8.3.3rc1
8.3.3
8.3.4rc1
8.3.4
8.4.0rc1
8.4.0
8.4.1rc1
8.4.1
8.4.2rc1
8.4.2
9.*
9.0.0rc1
9.0.0
9.0.1rc1
9.0.1
10.*
10.0.0rc1
10.0.0
10.0.1rc1
10.0.1
10.1.0rc1
10.1.0rc2
10.1.0
10.2.0
10.3.0rc1
10.3.0
10.3.1rc1
10.3.1
10.4.0b1
10.4.0rc1
10.4.0
10.4.1rc1
10.4.1
10.4.2rc1
10.4.2
10.4.3rc1
10.4.3
10.5.0rc1
10.5.0rc2
10.5.0
10.6.0rc1
10.6.0
10.6.1rc1
10.6.1
10.6.2rc1
10.6.2
10.7.0rc1
10.7.0
10.8.0rc1
10.8.0
10.8.1rc1
10.8.1
10.8.2rc1
10.8.2
10.9.0rc1
10.9.0
10.10.0rc1
10.10.0
10.11.0rc1
10.11.0rc2
10.11.0
10.11.1rc1
10.11.1
10.12.0rc1
10.12.0
10.12.1rc1
10.12.1
10.12.2rc2
10.12.2
10.12.3rc1
10.12.3
10.12.4rc1
10.12.4
10.13.0rc1
10.13.0
10.14.0rc1
10.14.0
10.15.0rc1
10.15.0
10.16.0rc1
10.16.0
10.16.1rc1
10.16.1
10.17.0rc1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-524w-vq63-2xhf/GHSA-524w-vq63-2xhf.json"