GHSA-f643-3rc2-j27wMediumCVSS 6.5
Apache Airflow exposes dict-valued var.json secrets in Rendered Templates
🔗 CVE IDs covered (1)
📋 Description
Apache Airflow's secrets masker did not mask var.json Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an isinstance(str) guard — so a secret stored as a JSON Variable and referenced in a template via var.json was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.
🎯 Affected products1
- pip/apache-airflow:< 3.3.1
🔗 References (10)
- https://nvd.nist.gov/vuln/detail/CVE-2026-59244
- https://github.com/apache/airflow/pull/68975
- https://lists.apache.org/thread/fncod6vttfo5fvmfs3h9r8s2kmm9j1n6
- http://www.openwall.com/lists/oss-security/2026/08/12/7
- https://github.com/apache/airflow/commit/917a086be848943aaaaa577b927e381f2dc1e99f
- https://github.com/apache/airflow/commit/aee182636d0b10a95d94400f7d8b3228dc2c802f
- https://github.com/apache/airflow/commit/b23955afc5c74386a092a1be5bcd376751c3c8a9
- https://github.com/apache/airflow/releases/tag/3.3.1
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2026-3706.yaml
- https://github.com/advisories/GHSA-f643-3rc2-j27w