CVE-2026-25219
published 2026-04-15CVE-2026-25219: The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.55%
42.3th percentile
The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, as well as when Connection was accidentaly logged to logs, those values could be seen in the logs. Azure Service Bus used those properties to store sensitive values. Possibly other providers could be also affected if they used the same fields to store sensitive data.
If you used Azure Service Bus connection with those values set or if you have other connections with those values storing sensitve values, you should upgrade Airflow to 3.1.8
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 3.2.0 | 3.2.0 |
| apache_software_foundation | apache_airflow | < 3.1.8 | 3.1.8 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4g48-54q2-fg7q: The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker
ghsa_unreviewed·2026-04-15
CVE-2026-25219 [MEDIUM] CWE-200 GHSA-4g48-54q2-fg7q: The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker
The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, as well as when Connection was accidentaly logged to logs, those values could be seen in the logs. Azure Service Bus used those properties to store sensitive values. Possibly other providers could be also affected if they used the same fields to store sensitive data.
If you used Azure Service Bus connection with those values set or if you have other connections with those values storing sensitve values, you should upgrade Airflow to 3.1.8
VulDB
Apache Airflow up to 3.1.7 Azure Service Bus access_key/connection_string information disclosure
vuldb·2026-04-15·CVSS 6.5
CVE-2026-25219 [MEDIUM] Apache Airflow up to 3.1.7 Azure Service Bus access_key/connection_string information disclosure
A vulnerability was found in Apache Airflow up to 3.1.7 and classified as problematic. This impacts an unknown function of the component Azure Service Bus. Executing a manipulation of the argument access_key/connection_string can lead to information disclosure.
This vulnerability appears as CVE-2026-25219. The attacker needs to be present on the local network. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
ghsa·2026-04-15
CVE-2026-25219 [MEDIUM] CWE-200 Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, as well as when Connection was accidently logged to logs, those values could be seen in the logs. Azure Service Bus used those properties to store sensitive values. Possibly other providers could be also affected if they used the same fields to store sensitive data.
If you used Azure Service Bus connection with those values set or if you have other connections with those values storing senesitve values, you should upgrade Airflow to 3.1.8.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-15
Published