Apache Airflow Stack Trace Exposure Vulnerability

Vulnerability

A vulnerability exists in Apache Airflow versions prior to 3.2.0, where SQL error stack traces were exposed through the API, regardless of the 'api/expose_stack_traces' setting. This exposure could provide additional information to potential attackers.

Impact

The vulnerability could lead to the unintentional disclosure of sensitive information, such as SQL statements and error details, which could be leveraged by an attacker.

Remediation

Users are advised to upgrade to Apache Airflow version 3.2.0 or later, which addresses this vulnerability.

Added: Apr 18, 2026, 7:20 AM
Updated: Apr 18, 2026, 7:20 AM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
7.4
remediation
7.7
relevance
6.0
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.