Sensitive Data Exposure in Apache Airflow's Secrets Masker
CVE-2026-59244
Currently unrated
What is CVE-2026-59244?
Apache Airflow features a secrets masker that fails to obscure var.json Variable values when they are structured as dictionaries within the Rendered Templates UI. This oversight allows sensitive information stored as a JSON Variable to be exposed in cleartext to any user with access to the task's Rendered Templates view, thus presenting a risk for unauthorized information disclosure. To mitigate this issue, users are encouraged to upgrade to Apache Airflow version 3.3.1 or later, which rectifies this vulnerability by ensuring that nested Variable values, regardless of their data type, are properly masked.
Affected Version(s)
Apache Airflow 0 < 3.3.1