Information disclosure in Apache Airflow - CVE-2026-54183
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper handling of recursion-depth limits in the secrets masker in the Variables UI when rendering deeply nested variable values stored inside a list, tuple, or set. A remote user can view a variable in the UI to disclose sensitive information.
The exposure is limited to values displayed in the UI and does not bypass existing access controls.