Information disclosure in Apache Airflow - CVE-2026-54183

 

Information disclosure in Apache Airflow - CVE-2026-54183

Published: August 24, 2026


Vulnerability identifier: #VU144875
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54183
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper handling of recursion-depth limits in the secrets masker in the Variables UI when rendering deeply nested variable values stored inside a list, tuple, or set. A remote user can view a variable in the UI to disclose sensitive information.

The exposure is limited to values displayed in the UI and does not bypass existing access controls.


Affected software

Apache Airflow

How to mitigate CVE-2026-54183

Install security update from vendor's website.

Apache Airflow - update to 3.3.1

External References

Related Security Bulletins