CVE-2025-68438

In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This occurred because serialization of those fields used a secrets masker instance that did not include user-registered mask_secret() patterns, so secrets were not reliably masked before truncation and display. Users are recommended to upgrade to 3.1.6 or later, which fixes this issue
References
Link Resource
https://lists.apache.org/thread/55n7b4nlsz3vo5n4h5lrj9bfsk8ctyff Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/01/15/5 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:59

Type Values Removed Values Added
Summary
  • (es) En versiones de Apache Airflow anteriores a la 3.1.6, cuando los campos de plantilla renderizados en un DAG exceden [core] max_templated_field_length, valores sensibles podrían quedar expuestos en texto claro en la interfaz de usuario de Plantillas Renderizadas. Esto ocurrió porque la serialización de esos campos utilizaba una instancia de enmascarador de secretos que no incluía patrones mask_secret() registrados por el usuario, por lo que los secretos no se enmascaraban de forma fiable antes de la truncación y visualización. Se recomienda a los usuarios actualizar a la 3.1.6 o posterior, lo que corrige este problema.

21 Jan 2026, 13:44

Type Values Removed Values Added
First Time Apache airflow
Apache
CPE cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
References () https://lists.apache.org/thread/55n7b4nlsz3vo5n4h5lrj9bfsk8ctyff - () https://lists.apache.org/thread/55n7b4nlsz3vo5n4h5lrj9bfsk8ctyff - Mailing List, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/01/15/5 - () http://www.openwall.com/lists/oss-security/2026/01/15/5 - Mailing List, Third Party Advisory

16 Jan 2026, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

16 Jan 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 11:16

Updated : 2026-06-17 09:59


NVD link : CVE-2025-68438

Mitre link : CVE-2025-68438

CVE.ORG link : CVE-2025-68438


JSON object : View

Products Affected

apache

  • airflow
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor