PT-2026-56180 · Apache · Apache Airflow

·

CVE-2026-49487

·

Published

2026-07-07

·

Updated

2026-07-12

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 3.3.0
Description The REST API task-instance detail and list endpoints return a deferred task's trigger kwargs without masking. This allows any authenticated user with DAG-scoped task-instance read access to view sensitive information, such as provider API keys, in clear text while the task is deferred.
Recommendations Upgrade to version 3.3.0 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2026-49487
CVE-2026-49487
GHSA-22HF-VX2V-GJFF
PYSEC-2026-2088

Affected Products

Apache Airflow