PT-2026-45372 · Apache · Apache Airflow

·

CVE-2026-42360

·

Published

2026-06-01

·

Updated

2026-06-05

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 3.2.2
Description A bug in the rendered-template field handling allows the bypass of nested sensitive-key masking. When a rendered field exceeds the [core] max templated field length limit, the software stringifies the structure before redaction, which removes the nested key context and results in plaintext values being persisted into rendered fields. This affects deployments where DAG authors pass structured JSON to operators containing nested sensitive keys such as password, token, secret, or api key. An authenticated UI or API user with permissions to read rendered template fields can harvest these secret values.
Recommendations Update to version 3.2.2 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2026-42360
CVE-2026-42360
ECHO-9B9A-E7B8-0E09
GHSA-CG3X-89RC-X9MW
PYSEC-2026-172

Affected Products

Apache Airflow