🔐 CVE Alert

CVE-2025-65995

MEDIUM 6.5

Apache Airflow: Disclosure of secrets to UI via kwargs

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to authenticated users who had permission to view that DAG.  The issue has been fixed in Airflow 3.1.4 and 2.11.1, and users are strongly advised to upgrade to prevent potential disclosure of sensitive information.

CWE CWE-209
Vendor apache software foundation
Product apache airflow
Published Feb 21, 2026
Last Updated Mar 8, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache airflow

Be the first to know when new medium vulnerabilities affecting apache software foundation apache airflow are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache Airflow
3.0.0 < 3.1.4 0 < 2.11.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/apache/airflow/pull/58252 lists.apache.org: https://lists.apache.org/thread/1qzlrjo2wmlzs0rrgzgslj2pzkor0dr2 github.com: https://github.com/apache/airflow/pull/61883 openwall.com: http://www.openwall.com/lists/oss-security/2025/12/12/2

Credits

Frieder Gottman (Cariad) 🔍 Jens Scheffler (Bosch) Jens Scheffler (Bosch)