PT-2026-33595 · Apache · Apache Airflow

Kevin Yang

·

Published

2026-04-18

·

Updated

2026-04-18

·

CVE-2026-32690

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked.
If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2026-32690

Affected Products

Apache Airflow