CVE-2026-32690
published 2026-04-18CVE-2026-32690: Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested…
PriorityP416low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
EPSS
0.42%
34.0th percentile
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked.
If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 3.2.2 | 3.2.2 |
| apache | airflow | >= 3.0.0 < 3.2.0 | 3.2.0 |
| apache_software_foundation | apache_airflow | < 3.2.2 | 3.2.2 |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
ghsa3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
ghsa·2026-06-01·CVSS 3.7
CVE-2026-42358 [LOW] CWE-200 Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `secret`, `api_key`) to be bypassed when the JSON value's nesting depth exceeded the shared secrets masker's recursion limit: the masker returned the original nested item before checking the sensitive key name. An authenticated UI/API user with Variable read permission could harvest plaintext secret values stored under sensitive keys nested deep enough to exceed the masker's depth cap. Affects deployments that store sensitive values inside deeply-nested JSON Variables. This is a residual gap in the fix for CVE-2026-32690 (which covered shallower nesting via `m
GHSA
A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `secret`, `api_key`) to be bypassed when the JSON value
ghsa_unreviewed·2026-06-01·CVSS 3.7
CVE-2026-42358 [LOW] CWE-200 A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `secret`, `api_key`) to be bypassed when the JSON value
A bug in Apache Airflow's Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `secret`, `api_key`) to be bypassed when the JSON value's nesting depth exceeded the shared secrets masker's recursion limit: the masker returned the original nested item before checking the sensitive key name. An authenticated UI/API user with Variable read permission could harvest plaintext secret values stored under sensitive keys nested deep enough to exceed the masker's depth cap. Affects deployments that store sensitive values inside deeply-nested JSON Variables. This is a residual gap in the fix for CVE-2026-32690 (which covered shallower nesting via `max_depth=1`); the depth-limit boundary itself was not raised, so the same key-name bypass
GHSA
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
ghsa·2026-04-18
CVE-2026-32690 [LOW] CWE-668 Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked.
If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0.
GHSA
GHSA-w9r4-94fj-xp69: Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as n
ghsa_unreviewed·2026-04-18
CVE-2026-32690 CWE-668 GHSA-w9r4-94fj-xp69: Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as n
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked.
If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented
VulDB
Apache Airflow up to 3.1.x JSON Dictionary information disclosure
vuldb·2026-04-17
CVE-2026-32690 [LOW] Apache Airflow up to 3.1.x JSON Dictionary information disclosure
A vulnerability classified as problematic has been found in Apache Airflow up to 3.1.x. This affects an unknown part of the component JSON Dictionary Handler. This manipulation causes information disclosure.
This vulnerability appears as CVE-2026-32690. The attacker needs to be present on the local network. There is no available exploit.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-18
Published