{"id":"CVE-2026-27173","aliases":["GHSA-524w-vq63-2xhf","PYSEC-2026-2365"],"url":"https://o3.security/vulnerability/CVE-2026-27173","summary":"Apache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line Arguments","details":"JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for tasks.","published":"2026-05-19T19:19:00.266Z","modified":"2026-08-12T03:51:19.134063899Z","cvss":{"score":8.7,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L"},"epss":{"score":0.00156,"percentile":0.05305,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"apache-airflow-providers-cncf-kubernetes","fixedVersion":"10.17.0"}],"fix":{"url":"https://github.com/apache/airflow/pull/60108","label":"apache/airflow#60108"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/05/19/35"},{"type":"WEB","url":"https://pypi.python.org"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27173.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/pk3m2z4s2rkmc0v6gh9hnch9spc6stqw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27173"},{"type":"FIX","url":"https://github.com/apache/airflow/pull/60108"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:19.134063899Z"}}