Data Exposure Flaw in Apache Airflow Task SDK Reveals Secrets
CVE-2026-68970
Currently unrated
What is CVE-2026-68970?
The Task SDK in Apache Airflow is susceptible to a data exposure vulnerability where the contents of a Variable formatted as a JSON list are not masked. When these unmasked values appear in task logs or the Rendered Templates UI, it poses a risk of sensitive information leakage. Authenticated users with access to view logs or templates can retrieve these secrets without any extra configuration. The issue arises because masking only applies to strings and dictionaries, leaving list-type values exposed. Upgrading to Apache Airflow version 3.3.1 or later is highly recommended for mitigation.
Affected Version(s)
Apache Airflow 0 < 3.3.1