PT-2026-71138 · Apache · Apache Airflow

·

CVE-2026-54183

·

Published

2026-08-12

·

Updated

2026-08-17

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 3.3.1
Description The secrets masker in the UI fails to hide values stored under sensitive key names when they are nested inside a list, tuple, or set beyond the recursion-depth limit. This results in Airflow Variables with deeply-nested values being displayed unmasked in the Variables UI. This issue serves as a shoulder-surfing defense and does not bypass access-control boundaries, as authenticated users with UI access can already retrieve the full value via the Variables REST API.
Recommendations Upgrade to apache-airflow version 3.3.1 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2026-54183
CVE-2026-54183
PYSEC-2026-3705

Affected Products

Apache Airflow