VYPR
High severity7.5NVD Advisory· Published Apr 18, 2026· Updated Apr 21, 2026

CVE-2026-30912

CVE-2026-30912

Description

In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
apache-airflow-corePyPI
< 3.2.03.2.0

Affected products

1
  • cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
    Range: <3.2.0

Patches

1

Vulnerability mechanics

Generated by null/stub on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

5

News mentions

0

No linked articles in our index yet.