Vulnerability GHSA-f643-3rc2-j27w
Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 month ago
August 12, 2026 at 06:31 PM UTC
Apache Airflow exposes dict-valued var.json secrets in Rendered Templates
1.8.1 - 3.3.1rc2
1.8.1 - 3.3.1rc2
Summary
Apache Airflow exposes dict-valued var.json secrets in Rendered Templates
Details
Apache Airflow's secrets masker did not mask var.json Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an isinstance(str) guard — so a secret stored as a JSON Variable and referenced in a template via var.json was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
11 days ago
No summary available
1.8.1 - 3.3.0 and 3.3.1 PYSEC-2026-3989
1.8.1 - 3.3.0 and 3.3.1 PYSEC-2026-3989
Critical
11 days ago
No summary available
3.0.0 - 3.3.2rc1 PYSEC-2026-3990
3.0.0 - 3.3.2rc1 PYSEC-2026-3990
Medium Risk
11 days ago
No summary available
1.8.1 - 3.3.2rc1 PYSEC-2026-3988
1.8.1 - 3.3.2rc1 PYSEC-2026-3988
Medium Risk
22 days ago
Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API
1.8.1 - 3.3.0rc2 PYSEC-2026-3806
1.8.1 - 3.3.0rc2 PYSEC-2026-3806
Medium Risk
1 month ago
Apache Airflow missing team context permits cross-team Dag actions and XCom reads
1.8.1 - 3.3.1rc2 GHSA-5247-m8w9-2v4m
1.8.1 - 3.3.1rc2 GHSA-5247-m8w9-2v4m
Impacted packages
Timeline
Published
1 month ago
August 12, 2026 at 06:31 PM UTC
Fixed (3.3.1)
1 month ago
August 12, 2026 at 08:10 AM UTC
Last Modified
9 hours ago
October 02, 2026 at 11:30 PM UTC