Information disclosure in Apache Airflow - CVE-2026-32690
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper redaction in variable secret masking when retrieving variables saved as JSON dictionaries with nested secret fields. A remote user can retrieve a specially crafted variable value to disclose sensitive information.
Only variables storing sensitive values in JSON form with nested fields are affected.