Vulnerability PYSEC-2026-3706
Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 month ago
August 12, 2026 at 04:17 PM UTC
No summary available
1.8.1 - 3.3.1rc2
1.8.1 - 3.3.1rc2
Details
Apache Airflow's secrets masker did not mask var.json Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an isinstance(str) guard — so a secret stored as a JSON Variable and referenced in a template via var.json was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
13 days ago
No summary available
1.8.1 - 3.3.0 and 3.3.1 PYSEC-2026-3989
1.8.1 - 3.3.0 and 3.3.1 PYSEC-2026-3989
Critical
13 days ago
No summary available
3.0.0 - 3.3.2rc1 PYSEC-2026-3990
3.0.0 - 3.3.2rc1 PYSEC-2026-3990
Medium Risk
13 days ago
No summary available
1.8.1 - 3.3.2rc1 PYSEC-2026-3988
1.8.1 - 3.3.2rc1 PYSEC-2026-3988
Medium Risk
24 days ago
Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API
1.8.1 - 3.3.0rc2 PYSEC-2026-3806
1.8.1 - 3.3.0rc2 PYSEC-2026-3806
Medium Risk
1 month ago
Apache Airflow missing team context permits cross-team Dag actions and XCom reads
1.8.1 - 3.3.1rc2 GHSA-5247-m8w9-2v4m
1.8.1 - 3.3.1rc2 GHSA-5247-m8w9-2v4m
Impacted packages
Timeline
Published
1 month ago
August 12, 2026 at 04:17 PM UTC
Fixed (3.3.1)
1 month ago
August 12, 2026 at 08:10 AM UTC
Last Modified
1 day ago
October 02, 2026 at 11:40 PM UTC