Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w7cf-2pmc-5m4c | Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false |
Tue, 21 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* |
Mon, 20 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sat, 18 Apr 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow |
|
| Vendors & Products |
Apache
Apache airflow |
Sat, 18 Apr 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 18 Apr 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. | |
| Title | Apache Airflow: Exposing stack trace in case of constraint error | |
| Weaknesses | CWE-668 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-04-20T16:26:07.128Z
Reserved: 2026-03-07T13:49:05.584Z
Link: CVE-2026-30912
Updated: 2026-04-18T06:28:57.510Z
Status : Analyzed
Published: 2026-04-18T07:16:10.427
Modified: 2026-04-21T14:42:49.920
Link: CVE-2026-30912
No data.
OpenCVE Enrichment
Updated: 2026-04-20T18:45:14Z
Github GHSA