Data Exposure Flaw in Apache Airflow Task SDK Reveals Secrets
CVE-2026-68970

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
12 August 2026

What is CVE-2026-68970?

The Task SDK in Apache Airflow is susceptible to a data exposure vulnerability where the contents of a Variable formatted as a JSON list are not masked. When these unmasked values appear in task logs or the Rendered Templates UI, it poses a risk of sensitive information leakage. Authenticated users with access to view logs or templates can retrieve these secrets without any extra configuration. The issue arises because masking only applies to strings and dictionaries, leaving list-type values exposed. Upgrading to Apache Airflow version 3.3.1 or later is highly recommended for mitigation.

Affected Version(s)

Apache Airflow 0 < 3.3.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Raphael Zanarelli (@zanarellidev)
Jarek Potiuk
.