CVE-2025-65995
Apache Airflow: Disclosure of secrets to UI via kwargs
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to authenticated users who had permission to view that DAG. The issue has been fixed in Airflow 3.1.4 and 2.11.1, and users are strongly advised to upgrade to prevent potential disclosure of sensitive information.
| CWE | CWE-209 |
| Vendor | apache software foundation |
| Product | apache airflow |
| Published | Feb 21, 2026 |
| Last Updated | Mar 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache airflow
Be the first to know when new medium vulnerabilities affecting apache software foundation apache airflow are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Apache Software Foundation / Apache Airflow
3.0.0 < 3.1.4 0 < 2.11.1
References
Credits
Frieder Gottman (Cariad) 🔍 Jens Scheffler (Bosch) Jens Scheffler (Bosch)