Information disclosure in Apache Airflow - CVE-2026-45192
Published: June 4, 2026
Apache Airflow
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the GET /api/v2/connections/{connection_id} REST API endpoint when returning Connection extra JSON fields. A remote user can send a request for a connection record to disclose sensitive information.
The issue affects secrets stored in a Connection's extra JSON blob under field names not present in the redaction allowlist, and user access to read the connection is required.