Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. apache-airflow
  4. ›
  5. CVE-2025-66236

CVE-2025-66236: Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI

April 13, 2026 (updated April 14, 2026)

Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager could make were not clear or explicit enough, even though Airflow’s intentions and security model of Airflow did not suggest different assumptions. The overall security model, workload isolation, and JWT authentication details are now described in more detail. Users concerned with role isolation and following the Airflow security model of Airflow are advised to upgrade to Airflow 3.2, where several security improvements have been implemented. They should also read and follow the relevant documents to make sure that their deployment is secure enough. It also clarifies that the Deployment Manager is ultimately responsible for securing your Airflow deployment. This had also been communicated via Airflow 3.2.0 Blog announcement.

Users are recommended to upgrade to version 3.2.0, which fixes this issue.

References

  • airflow.apache.org/blog/airflow-3.2.0
  • github.com/advisories/GHSA-j86x-fwp2-qh7v
  • github.com/apache/airflow
  • github.com/apache/airflow/pull/58662
  • lists.apache.org/thread/g8fyy1tkmxkkfk7tx2v6h8mvwzpyykbo
  • nvd.nist.gov/vuln/detail/CVE-2025-66236

Code Behaviors & Features

Detect and mitigate CVE-2025-66236 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.2.0

Fixed versions

  • 3.2.0

Solution

Upgrade to version 3.2.0 or above.

Impact 4.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-532: Insertion of Sensitive Information into Log File

Source file

pypi/apache-airflow/CVE-2025-66236.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:20:15 +0000.