Junglewise Threat Intelligence

CVE-2025-68438: Apache Airflow information disclosure in Rendered Templates UI

CVE-2025-68438 · Severity: high · CVSS 7.5 · Published 2026-01-16

Technologies: Apache Airflow, apache-airflow (PyPI). Vendors: Apache, PyPI.

Executive brief

Apache Airflow, a platform used to schedule and monitor workflows, contains a vulnerability where sensitive information like passwords or API keys could be exposed in the management interface. When certain data fields are very long, the system's automatic masking feature may fail, displaying secrets in plain text to users with access to the Rendered Templates UI. This could lead to unauthorized access to external systems or sensitive corporate data.

Technical details

In Apache Airflow versions 3.1.0 through 3.1.5, sensitive values may be exposed in cleartext within the Rendered Templates UI. The vulnerability occurs when rendered template fields exceed the configured '[core] max_templated_field_length'. During serialization for display, the system uses a secrets masker instance that fails to incorporate user-registered 'mask_secret()' patterns. Consequently, if a field is truncated due to its length, the masking logic is bypassed, allowing sensitive data to be viewed by any user with access to the DAG's rendered templates. This is classified as CWE-200 (Exposure of Sensitive Information). The issue is resolved in version 3.1.6.

Affected products

  • Apache Airflow >= 3.1.0, < 3.1.6

Timeline

  • 2026-01-15: disclosed: Initial disclosure on oss-security mailing list
  • 2026-01-16: advisory: GitHub and NVD advisories published
  • 2026-01-16: patched: Version 3.1.6 released

References

Related threats