PT-2026-21640 · Apache · Airflow

Sw0Rd1Ight

·

Published

2026-02-23

·

Updated

2026-03-11

·

CVE-2025-27555

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Airflow versions prior to 2.11.1
Description The software contains a flaw that permits authenticated users possessing audit log access to view sensitive values within audit logs that they are not authorized to see. Specifically, when sensitive connection parameters were established through the Airflow command-line interface (CLI), the values of these variables were exposed in the audit log and stored unencrypted within the Airflow database. This risk is confined to users with audit log access. The issue concerns connection secrets not being masked in the user interface when connections are added via the CLI.
Recommendations Upgrade to Airflow version 2.11.1 or a later version. Manually delete entries containing sensitive connection values from the log table for users who previously used the CLI to set connections.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2025-27555
CVE-2025-27555
GHSA-8R55-RV5W-6PFM

Affected Products

Airflow