CVE Database
/

CVE-2025-68438

Back to search

CVE-2025-68438

Published: Jan 16, 2026

Modified: Jan 16, 2026

PUBLISHED

Description

In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This occurred because serialization of those fields used a secrets masker instance that did not include user-registered mask_secret() patterns, so secrets were not reliably masked before truncation and display. Users are recommended to upgrade to 3.1.6 or later, which fixes this issue

VendorProductVersions

Apache Software Foundation

Apache Airflow

affected
3.1.0 - < 3.1.6

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now