CVE-2026-32690
Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented
| CWE | CWE-668 |
| Vendor | apache software foundation |
| Product | apache airflow |
| Published | Apr 18, 2026 |
| Last Updated | Apr 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache airflow
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache airflow are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache Airflow
3.0.0 < 3.2.0
References
Credits
Nguyen Anh Binh [IA Lab โ FPT University] Kevin Yang