Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. apache-airflow
  4. ›
  5. CVE-2025-68438

CVE-2025-68438: Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated

January 16, 2026 (updated June 5, 2026)

In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This occurred because serialization of those fields used a secrets masker instance that did not include user-registered mask_secret() patterns, so secrets were not reliably masked before truncation and display.

Users are recommended to upgrade to 3.1.6 or later, which fixes this issue

References

  • github.com/advisories/GHSA-3qmm-r55x-hpxx
  • github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2026-9.yaml
  • lists.apache.org/thread/55n7b4nlsz3vo5n4h5lrj9bfsk8ctyff
  • nvd.nist.gov/vuln/detail/CVE-2025-68438

Code Behaviors & Features

Detect and mitigate CVE-2025-68438 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.1.0 before 3.1.6

Fixed versions

  • 3.1.6

Solution

Upgrade to version 3.1.6 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Source file

pypi/apache-airflow/CVE-2025-68438.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 24 Jun 2026 00:17:50 +0000.