Apache Airflow exposes secret values to authenticated UI users via rendered templates
Moderate severity
GitHub Reviewed
Published
Dec 15, 2025
to the GitHub Advisory Database
•
Updated Dec 16, 2025
Description
Published by the National Vulnerability Database
Dec 15, 2025
Published to the GitHub Advisory Database
Dec 15, 2025
Reviewed
Dec 16, 2025
Last updated
Dec 16, 2025
A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redacted, potentially exposing secrets to users without the appropriate authorization.
Users are recommended to upgrade to version 3.1.4, which fixes this issue.
References