PT-2025-51040 · Apache · Apache Airflow

Amogh Desai

+1

·

Published

2025-12-12

·

Updated

2025-12-16

·

CVE-2025-66388

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 3.1.4
Description A flaw exists in Apache Airflow where authenticated users of the user interface could view secret values within rendered templates. This occurred because secrets were not properly redacted, potentially granting unauthorized access to sensitive information.
Recommendations Upgrade to version 3.1.4 to resolve this issue.

Fix

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2025-66388
CVE-2025-66388
GHSA-FV47-PQH6-WXGQ
PYSEC-2025-86

Affected Products

Apache Airflow