๐Ÿ” CVE Alert

CVE-2026-45192

MEDIUM 6.5

Apache Airflow: Incomplete Redaction of Sensitive Fields in Connection Extra API Response

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apache Airflow allowed an authenticated UI/API user with Connection-read permission to retrieve secrets stored in a Connection's `extra` JSON blob under field names not present in the redaction allowlist (`DEFAULT_SENSITIVE_FIELDS`) โ€” for example, official Slack-provider credential field names were returned in plaintext. Affects deployments that store credentials in Connection `extra` blobs and grant Connection-read access to multiple users. Users are advised to upgrade to `apache-airflow` 3.2.2 or later. As a defense-in-depth mitigation, deployment operators can store sensitive credential values in a secret-backend rather than inlined into the Connection's `extra` field.

CWE CWE-200
Vendor apache software foundation
Product apache airflow
Published Jun 1, 2026
Last Updated Jun 1, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache airflow

Be the first to know when new medium vulnerabilities affecting apache software foundation apache airflow are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Airflow
0 < 3.2.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/airflow/pull/66673 lists.apache.org: https://lists.apache.org/thread/r2q93dg2wp5h9sd9vh6y4y5ljqd9crdd openwall.com: http://www.openwall.com/lists/oss-security/2026/06/01/3

Credits

Or Sahar, Secure From Scratch Jarek Potiuk (@potiuk)