CVE-2026-59244
CVE-2026-59244: 2 tracked advisory records across Apache. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
2 advisories- Advisory severityMedium6.5
Medium [CVE-2026-59244] Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI
CVE-2026-59244Source published Source updated
Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.
- Affected products in this advisory
- Apache Airflow
- Source-reported affected versions
- Apache Airflow before 3.3.1
- Source-reported fixed versions
- 3.3.1
- Mitigation guidance
- Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.
- Advisory severityMedium6.5
Medium [CVE-2026-59244 +1] Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI
CVE-2026-68970Source published Source updated
This bulletin covers 2 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was returned unmasked. Any authenticated user able to read the logs or rendered templates of a task that references such a Variable could recover the values, with no special configuration required. This is the list-shaped counterpart of CVE-2026-59244, whose fix covered the dict case only, so deployments that upgraded in response to that advisory remain affected and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later.
- Affected products in this advisory
- Apache Airflow
- Source-reported affected versions
- Apache Airflow before 3.3.1
- Source-reported fixed versions
- 3.3.1
- Mitigation guidance
- This is the list-shaped counterpart of CVE-2026-59244, whose fix covered the dict case only, so deployments that upgraded in response to that advisory remain affected and must upgrade again.
- Users are advised to upgrade to apache-airflow 3.3.1 or later.
Android app · Google Play
Monitor future Apache CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.