Sensitive Data Exposure in Apache Airflow's Secrets Masker
CVE-2026-59244

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
12 August 2026

What is CVE-2026-59244?

Apache Airflow features a secrets masker that fails to obscure var.json Variable values when they are structured as dictionaries within the Rendered Templates UI. This oversight allows sensitive information stored as a JSON Variable to be exposed in cleartext to any user with access to the task's Rendered Templates view, thus presenting a risk for unauthorized information disclosure. To mitigate this issue, users are encouraged to upgrade to Apache Airflow version 3.3.1 or later, which rectifies this vulnerability by ensuring that nested Variable values, regardless of their data type, are properly masked.

Affected Version(s)

Apache Airflow 0 < 3.3.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Juan Pablo Guereca (@jpgerek)
Juan Pablo Guereca (@jpgerek)
.