Sensitive Configuration Exposure in Apache Airflow Due to Insufficient Masking
CVE-2026-65017
What is CVE-2026-65017?
The Config API of Apache Airflow fails to adequately mask team-scoped sensitive configuration values in deployments utilizing multi-team functionality. When multi-team mode is enabled and the Config API is accessible, an authenticated user with limited configuration-read permissions can potentially retrieve a cleartext team-scoped Celery broker URL alongside its embedded credentials. This occurs due to the inadequate normalization of team-prefixed configurations during the sensitivity check. Importantly, users who have updated to apache-airflow version 3.3.0 in response to previous vulnerabilities remain susceptible to this specific issue. To protect against this vulnerability, it is essential to upgrade to apache-airflow version 3.3.1 or later, which addresses these normalization shortfalls.
Affected Version(s)
Apache Airflow 3.3.0 < 3.3.1