oss-sec mailing list archives

CVE-2025-65995: Apache Airflow: Disclosure of secrets to UI via kwargs


From: Ephraim Anierobi <ephraimanierobi () apache org>
Date: Fri, 12 Dec 2025 09:04:06 +0000

Severity: moderate 

Affected versions:

- Apache Airflow (apache-airflow) before 3.1.4

Description:

When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the 
operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to 
authenticated users who had permission to view that DAG. 

The issue has been fixed in Airflow 3.1.4, and users are strongly advised to upgrade to prevent potential disclosure of 
sensitive information.

Credit:

Frieder Gottman (Cariad) (finder)
Jens Scheffler (Bosch) (reporter)
Jens Scheffler (Bosch) (remediation developer)

References:

https://github.com/apache/airflow/pull/58252
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2025-65995


Current thread: