CVE-2026-59244

⚪ Do wiadomości

Błąd w Apache Airflow ujawnia sekrety w interfejsie Rendered Templates dla zmiennych JSON.

CVSS
6.5
EPSS
0.2%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-08-12 16:17:09 UTC
Ostatnia modyfikacja (NVD)2026-09-16 15:17:39 UTC
Referencje