Sensitive Configuration Exposure in Apache Airflow Due to Insufficient Masking
CVE-2026-65017

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
12 August 2026

What is CVE-2026-65017?

The Config API of Apache Airflow fails to adequately mask team-scoped sensitive configuration values in deployments utilizing multi-team functionality. When multi-team mode is enabled and the Config API is accessible, an authenticated user with limited configuration-read permissions can potentially retrieve a cleartext team-scoped Celery broker URL alongside its embedded credentials. This occurs due to the inadequate normalization of team-prefixed configurations during the sensitivity check. Importantly, users who have updated to apache-airflow version 3.3.0 in response to previous vulnerabilities remain susceptible to this specific issue. To protect against this vulnerability, it is essential to upgrade to apache-airflow version 3.3.1 or later, which addresses these normalization shortfalls.

Affected Version(s)

Apache Airflow 3.3.0 < 3.3.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Rukin (Arenadata)
Jarek Potiuk
.