In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* |
Mon, 20 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sat, 18 Apr 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow |
|
| Vendors & Products |
Apache
Apache airflow |
Sat, 18 Apr 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 18 Apr 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. | |
| Title | Apache Airflow: Exposing stack trace in case of constraint error | |
| Weaknesses | CWE-668 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published: 2026-04-18T06:20:30.254Z
Updated: 2026-04-20T16:26:07.128Z
Reserved: 2026-03-07T13:49:05.584Z
Link: CVE-2026-30912
Updated: 2026-04-18T06:28:57.510Z
Status : Analyzed
Published: 2026-04-18T07:16:10.427
Modified: 2026-04-21T14:42:49.920
Link: CVE-2026-30912
No data.