CVE-2025-68675
published 2026-01-16CVE-2025-68675: In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication…
PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.98%
78.2th percentile
In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log output. As a result, when such connections are rendered or printed to logs, proxy credentials embedded in these fields could be exposed.
Users are recommended to upgrade to 3.1.6 or later for Airflow 3, and 2.11.1 or later for Airflow 2 which fixes this issue
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 3.1.6 | 3.1.6 |
| apache_software_foundation | apache_airflow | < 2.11.1 | 2.11.1 |
| apache_software_foundation | apache_airflow | >= 3.0.0 < 3.1.6 | 3.1.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Airflow proxy credentials for various providers might leak in task logs
ghsa·2026-01-16
CVE-2025-68675 [HIGH] CWE-532 Apache Airflow proxy credentials for various providers might leak in task logs
Apache Airflow proxy credentials for various providers might leak in task logs
In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log output. As a result, when such connections are rendered or printed to logs, proxy credentials embedded in these fields could be exposed.
Users are recommended to upgrade to 3.1.6 or later for Airflow 3, and 2.11.1 or later for Airflow 2 which fixes this issue.
OSV
Apache Airflow proxy credentials for various providers might leak in task logs
osv·2026-01-16
CVE-2025-68675 [HIGH] Apache Airflow proxy credentials for various providers might leak in task logs
Apache Airflow proxy credentials for various providers might leak in task logs
In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log output. As a result, when such connections are rendered or printed to logs, proxy credentials embedded in these fields could be exposed.
Users are recommended to upgrade to 3.1.6 or later for Airflow 3, and 2.11.1 or later for Airflow 2 which fixes this issue.
No detection rules found.
No public exploits indexed.
2026-01-16
Published