OVERVIEW CVE-2025-57735 is a token invalidation vulnerability affecting Apache Airflow versions prior to 3.2. When users logged out, their JWT authentication tokens were not properly invalidated, allowing intercepted tokens to be reused for unauthorized access. This flaw was remediated in Airflow 3.2 through implementation of token invalidation mechanisms at logout. SEVERITY The vulnerability carries a CRITICAL CVSS score of 9.1 with a network-based attack vector, low complexity, and no authentication requirement. An attacker with network access could exploit intercepted tokens to gain high-impact unauthorized access to confidentiality and integrity of Airflow systems without requiring user interaction. The EPSS score of 0.000370 indicates low probability of exploitation in the wild relative to other CVEs, though this does not diminish the severity of potential impact. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed on the KEV catalog and shows inactive status on threat tracking lists. No known public exploit code is currently available, suggesting limited community attention or weaponization at present. Organizations should prioritize upgrading to Airflow 3.2.0 or later to eliminate this risk, particularly for internet-facing deployments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.2.0CPE match | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.