PT-2026-21640 · Apache · Airflow
Sw0Rd1Ight
·
Published
2026-02-23
·
Updated
2026-03-11
·
CVE-2025-27555
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Airflow versions prior to 2.11.1
Description
The software contains a flaw that permits authenticated users possessing audit log access to view sensitive values within audit logs that they are not authorized to see. Specifically, when sensitive connection parameters were established through the Airflow command-line interface (CLI), the values of these variables were exposed in the audit log and stored unencrypted within the Airflow database. This risk is confined to users with audit log access. The issue concerns connection secrets not being masked in the user interface when connections are added via the CLI.
Recommendations
Upgrade to Airflow version 2.11.1 or a later version.
Manually delete entries containing sensitive connection values from the log table for users who previously used the CLI to set connections.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Airflow