CVE-2026-32690
Vulnerability Description
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked.
If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented
If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-668
Source
NVD
Vendor
Apache Software Foundation
Product
Apache Airflow
Discussion (0)
Add Comment
No comments yet. Be the first!