PT-2026-3231 · Apache · Apache Airflow
Amogh Desai
+1
·
Published
2026-01-15
·
Updated
2026-01-21
·
CVE-2025-68438
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions prior to 3.1.6
Description
When rendered template fields in a Dag exceed
max templated field length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This is due to the serialization of these fields using a secrets masker instance that did not include user-registered mask secret() patterns, resulting in unreliable masking of secrets before truncation and display.Recommendations
Upgrade to version 3.1.6 or later to resolve this issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow