#VU121615 Inclusion of Sensitive Information in Log Files in Apache Airflow - CVE-2025-68675
Published: January 16, 2026
Apache Airflow
Apache Foundation
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software does not treat proxies and proxy fields within a Connection as sensitive although they may include proxy URLs with embedded authentication information. A local user can view task logs and obtain credentials in plain text.