๐Ÿ” CVE Alert

CVE-2026-32690

UNKNOWN 0.0

Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented

CWE CWE-668
Vendor apache software foundation
Product apache airflow
Published Apr 18, 2026
Last Updated Apr 18, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache airflow

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache airflow are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Airflow
3.0.0 < 3.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/airflow/pull/63480 lists.apache.org: https://lists.apache.org/thread/7rnzxofntcznqxnhsmjvvlvygwph7rn5 openwall.com: http://www.openwall.com/lists/oss-security/2026/04/17/6

Credits

Nguyen Anh Binh [IA Lab โ€“ FPT University] Kevin Yang