Vulnerability Description
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Airflow | < 3.2.0 |
Related Weaknesses (CWE)
References
- https://github.com/apache/airflow/pull/63028Issue Tracking
- https://lists.apache.org/thread/tp6kz1hnfb3zsrrtg19myo8x5x80w8r9Vendor AdvisoryMailing List
- http://www.openwall.com/lists/oss-security/2026/04/17/5Mailing ListThird Party Advisory
FAQ
What is CVE-2026-30912?
CVE-2026-30912 is a vulnerability with a CVSS score of 7.5 (HIGH). In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. ...
How severe is CVE-2026-30912?
CVE-2026-30912 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-30912?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Airflow.