Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 2 advisories

CVE-2026-59244

CVE-2026-59244: 2 tracked advisory records across Apache. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Apache

2 advisories
  • Advisory severityMedium6.5

    Medium [CVE-2026-59244] Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI

    CVE-2026-59244Source published Source updated

    Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.

    Affected products in this advisory
    • Apache Airflow
    Source-reported affected versions
    • Apache Airflow before 3.3.1
    Source-reported fixed versions
    • 3.3.1
    Mitigation guidance
    • Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.
  • Advisory severityMedium6.5

    Medium [CVE-2026-59244 +1] Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI

    CVE-2026-68970Source published Source updated

    This bulletin covers 2 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was returned unmasked. Any authenticated user able to read the logs or rendered templates of a task that references such a Variable could recover the values, with no special configuration required. This is the list-shaped counterpart of CVE-2026-59244, whose fix covered the dict case only, so deployments that upgraded in response to that advisory remain affected and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later.

    Affected products in this advisory
    • Apache Airflow
    Source-reported affected versions
    • Apache Airflow before 3.3.1
    Source-reported fixed versions
    • 3.3.1
    Mitigation guidance
    • This is the list-shaped counterpart of CVE-2026-59244, whose fix covered the dict case only, so deployments that upgraded in response to that advisory remain affected and must upgrade again.
    • Users are advised to upgrade to apache-airflow 3.3.1 or later.

Android app · Google Play

Monitor future Apache CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery