Unknown [CVE-2026-59244] Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI
This security Apache Software Foundation advisory covers CVE-2026-59244 affecting Apache Airflow.
Android app · Google Play
Monitor future Apache Software Foundation CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view.
Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.
- Apache Airflow before 3.3.1
Official advisory · medium-confidence parse· fetched 2 hours ago·verify at source
- 3.3.1
Official advisory · medium-confidence parse· fetched 2 hours ago·verify at source
Mitigation checklist
- Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.
Official advisory · medium-confidence parse· fetched 2 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.