Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ankit Chaurasia

#33578of 53,633
7.8Total CVSS
Vulnerabilities · 1
PT-2026-3232
7.8
2026-01-15
Apache · Apache Airflow · CVE-2025-68675
**Name of the Vulnerable Software and Affected Versions** Apache Airflow versions prior to 3.1.6 **Description** Apache Airflow versions before 3.1.6 did not properly handle sensitive information within proxy URLs in Connection objects. Specifically, proxy credentials embedded in the `proxies` and `proxy` fields were not automatically masked in log output, potentially exposing them when connections were rendered or printed to logs. **Recommendations** Upgrade to version 3.1.6 or later to resolve this issue.