External risk intelligence

Apache Airflow JWT Token Invalidation Logout Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-57735

Apache Airflow is commonly deployed as a centralized orchestration platform with a web-based user interface and API, which are frequently exposed to network access for internal or external users. The vulnerability involves session token management within this web-facing application interface.

Apache Airflow

3.0.0 to before 3.2.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory describes a vulnerability in Apache Airflow where a user's authentication token could be reused if intercepted after logout, potentially allowing unauthorized access. While a fix is available, the primary concern is to confirm if your environment uses the affected versions and if the logout functionality and token interception are relevant scenarios for your operations.

  • Logged-out tokens can be reused.
  • Critical vulnerability in session token handling.
  • Confirm Airflow usage and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this by intercepting a valid user's session token after they log out. This token, if not invalidated by the system, can be reused by the attacker to gain unauthorized access to the user's account and potentially perform actions as that user.

  • Token can be intercepted after logout.
  • Reused token grants unauthorized access.
  • Risk of account takeover and data compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to reuse a previously intercepted JWT token after a user logs out, potentially granting them unauthorized access to the affected system. This could occur if a token is intercepted while a user is still authenticated or during the logout process before the token is invalidated.

  • User session tokens at risk.
  • Token reuse after logout.
  • Unauthorized system access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Platform or application owners are responsible for addressing this vulnerability, as it affects the session token invalidation mechanism in Apache Airflow. The first practical step is to identify all Airflow instances, determine their reachability and criticality, confirm ownership, and then plan remediation based on these findings.

  • Confirm Airflow instance ownership and exposure.
  • Verify affected Airflow instances and their criticality.
  • Plan remediation, likely involving upgrades.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Apache Airflow?

Apache Airflow is an open-source platform used to programmatically author, schedule, and monitor complex data workflows and pipelines. It provides a centralized interface and API for orchestrating tasks across different systems, acting as the control plane for many data engineering environments.

What does CWE-613 mean for CVE-2025-57735?

CWE-613 identifies an Insufficient Session Expiration weakness. In this context, it means that when a user logs out of Airflow, the system fails to invalidate the JSON Web Token (JWT) used for that session. Because the token remains technically active on the server side, anyone who manages to obtain it can continue to use it as if they were the legitimate, authenticated user.

How can an attacker trigger this vulnerability?

An attacker needs to intercept a valid JWT session token. This could potentially occur if the token is captured while a user is authenticated or during the logout process. If a user logs out but the token remains valid, the captured token allows unauthorized access. This bug is not triggered by normal administrative tasks or simple configuration changes; it specifically relies on the reuse of a post-logout token.

Is my Airflow instance at risk?

If you run Apache Airflow versions 3.0.0 through 3.1.x, you are affected. According to Halo Surface Signal, Airflow is often deployed as a centralized orchestration platform with a web-based UI and API, which are frequently exposed to network access. If your instance is reachable over a network—whether internal or external—it is a potential target for session token misuse.

Do I need to update my software?

Yes, you should prioritize upgrading to Airflow version 3.2.0 or later. This version introduces the necessary mechanism to properly invalidate JWT tokens upon user logout, closing the window of opportunity for token reuse. Start by inventorying your Airflow instances to identify those running the affected versions and coordinate an upgrade to the patched release.

References