PT-2026-3231 · Apache · Apache Airflow

Amogh Desai

+1

·

Published

2026-01-15

·

Updated

2026-01-21

·

CVE-2025-68438

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 3.1.6
Description When rendered template fields in a Dag exceed max templated field length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This is due to the serialization of these fields using a secrets masker instance that did not include user-registered mask secret() patterns, resulting in unreliable masking of secrets before truncation and display.
Recommendations Upgrade to version 3.1.6 or later to resolve this issue.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-00683
BIT-AIRFLOW-2025-68438
CVE-2025-68438
GHSA-3QMM-R55X-HPXX

Affected Products

Apache Airflow