Executive brief
Apache Airflow's UI uses a secrets masker to hide sensitive values from shoulder-surfing when displaying Variables. Due to a recursion-depth limitation, deeply nested sensitive values stored within lists, tuples, or sets were displayed unmasked in the Variables UI. An authenticated user viewing the UI could see sensitive data that should have been redacted for visual protection, though the data remains accessible through the REST API to authenticated users.
Technical details
The vulnerability is an incomplete fix to CVE-2026-42358. The secrets masker walks dictionary structures unconditionally to find and redact sensitive key names at any depth, but lists, tuples, and sets beyond the recursion-depth limit were not traversed for key-name redaction. An attacker can view unmasked sensitive values in the Variables UI by nesting them inside iterables (lists, tuples, sets) deeper than the MAX_RECURSION_DEPTH threshold. The attack vector requires authentication and UI access; the exposure is limited to visual masking and does not bypass access controls since authenticated users can already retrieve the same data via the REST API. The fix involves walking nested iterables unconditionally for key-name redaction while maintaining the depth cutoff only for pattern-based string masking.
Affected products
- Apache Airflow before 3.3.1
Timeline
- 2026-08-12: disclosed
- 2026-06-25: patched: Fix merged in PR #68422