PT-2026-45372 · Apache · Apache Airflow
Jarek Potiuk
+1
·
Published
2026-06-01
·
Updated
2026-06-01
·
CVE-2026-42360
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Airflow versions prior to 3.2.2
Description
A bug in the rendered-template field handling allows the bypass of nested sensitive-key masking. When a rendered field exceeds the
[core] max templated field length limit, the software stringifies the structure before redaction, which removes the nested key context and results in plaintext values being persisted into rendered fields. This affects deployments where DAG authors pass structured JSON to operators containing nested sensitive keys such as password, token, secret, or api key. An authenticated UI or API user with permissions to read rendered template fields can harvest these secret values.Recommendations
Update to version 3.2.2 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow