DNA View

CVE-2026-25219

Medium
Low Medium High Critical
6.5
CVSS Score
Published: Apr 15, 2026
Last Modified: Apr 17, 2026

Vulnerability Description

The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, as well as when Connection was accidentaly logged to logs, those values could be seen in the logs. Azure Service Bus used those properties to store sensitive values. Possibly other providers could be also affected if they used the same fields to store sensitive data.

If you used Azure Service Bus connection with those values set or if you have other connections with those values storing sensitve values, you should upgrade Airflow to 3.1.8

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
N
Attack Complexity
L
Privileges Required
L
User Interaction
N
Scope
U
Confidentiality
H
Integrity
N
Availability
N

Known Affected Software

111 configuration(s) from 1 vendor(s)

airflow
Version:
1.10.5
CPE:
cpe:2.3:a:apache:airflow:1.10.5:*:*:*:*:*:*:*
airflow
Version:
2.3.0
CPE:
cpe:2.3:a:apache:airflow:2.3.0:*:*:*:*:*:*:*
airflow
Version:
2.2.3
CPE:
cpe:2.3:a:apache:airflow:2.2.3:*:*:*:*:*:*:*
airflow
Version:
1.2.0
CPE:
cpe:2.3:a:apache:airflow:1.2.0:*:*:*:*:*:*:*
airflow
Version:
2.7.0
CPE:
cpe:2.3:a:apache:airflow:2.7.0:*:*:*:*:*:*:*
airflow
Version:
2.10.2
CPE:
cpe:2.3:a:apache:airflow:2.10.2:rc1:*:*:*:*:*:*
airflow
Version:
3.1.5
CPE:
cpe:2.3:a:apache:airflow:3.1.5:-:*:*:*:*:*:*
airflow
Version:
2.3.3
CPE:
cpe:2.3:a:apache:airflow:2.3.3:*:*:*:*:*:*:*
airflow
Version:
2.1.2
CPE:
cpe:2.3:a:apache:airflow:2.1.2:*:*:*:*:*:*:*
airflow
Version:
3.0.0
CPE:
cpe:2.3:a:apache:airflow:3.0.0:rc4:*:*:*:*:*:*
airflow
Version:
2.8.4
CPE:
cpe:2.3:a:apache:airflow:2.8.4:-:*:*:*:*:*:*
airflow
Version:
1.6.0
CPE:
cpe:2.3:a:apache:airflow:1.6.0:*:*:*:*:*:*:*
airflow
Version:
1.10.11
CPE:
cpe:2.3:a:apache:airflow:1.10.11:*:*:*:*:*:*:*
airflow
Version:
3.0.3
CPE:
cpe:2.3:a:apache:airflow:3.0.3:-:*:*:*:*:*:*
airflow
Version:
1.10.10
CPE:
cpe:2.3:a:apache:airflow:1.10.10:*:*:*:*:*:*:*
airflow
Version:
0.2.2
CPE:
cpe:2.3:a:apache:airflow:0.2.2:*:*:*:*:*:*:*
airflow
Version:
2.10.4
CPE:
cpe:2.3:a:apache:airflow:2.10.4:rc1:*:*:*:*:*:*
airflow
Version:
0.4.6
CPE:
cpe:2.3:a:apache:airflow:0.4.6:*:*:*:*:*:*:*
airflow
Version:
3.1.6
CPE:
cpe:2.3:a:apache:airflow:3.1.6:-:*:*:*:*:*:*
airflow
Version:
3.1.3
CPE:
cpe:2.3:a:apache:airflow:3.1.3:-:*:*:*:*:*:*
airflow
Version:
0.4
CPE:
cpe:2.3:a:apache:airflow:0.4:*:*:*:*:*:*:*
airflow
Version:
1.8.0
CPE:
cpe:2.3:a:apache:airflow:1.8.0:*:*:*:*:*:*:*
airflow
Version:
1.10.14
CPE:
cpe:2.3:a:apache:airflow:1.10.14:*:*:*:*:*:*:*
airflow
Version:
2.10.3
CPE:
cpe:2.3:a:apache:airflow:2.10.3:rc2:*:*:*:*:*:*
airflow
Version:
3.1.1
CPE:
cpe:2.3:a:apache:airflow:3.1.1:-:*:*:*:*:*:*
airflow
Version:
1.10.9
CPE:
cpe:2.3:a:apache:airflow:1.10.9:*:*:*:*:*:*:*
airflow
Version:
3.0.2
CPE:
cpe:2.3:a:apache:airflow:3.0.2:-:*:*:*:*:*:*
airflow
Version:
2.2.4
CPE:
cpe:2.3:a:apache:airflow:2.2.4:*:*:*:*:*:*:*
airflow
Version:
2.4.1
CPE:
cpe:2.3:a:apache:airflow:2.4.1:*:*:*:*:*:*:*
airflow
Version:
2.3.4
CPE:
cpe:2.3:a:apache:airflow:2.3.4:*:*:*:*:*:*:*
airflow
Version:
1.8.1
CPE:
cpe:2.3:a:apache:airflow:1.8.1:*:*:*:*:*:*:*
airflow
Version:
0.1
CPE:
cpe:2.3:a:apache:airflow:0.1:*:*:*:*:*:*:*
airflow
Version:
1.10.13
CPE:
cpe:2.3:a:apache:airflow:1.10.13:*:*:*:*:*:*:*
airflow
Version:
2.8.1
CPE:
cpe:2.3:a:apache:airflow:2.8.1:*:*:*:*:*:*:*
airflow
Version:
1.5.0
CPE:
cpe:2.3:a:apache:airflow:1.5.0:*:*:*:*:*:*:*
airflow
Version:
1.10.15
CPE:
cpe:2.3:a:apache:airflow:1.10.15:*:*:*:*:*:*:*
airflow
Version:
0.2
CPE:
cpe:2.3:a:apache:airflow:0.2:*:*:*:*:*:*:*
airflow
Version:
2.2.0
CPE:
cpe:2.3:a:apache:airflow:2.2.0:beta1:*:*:*:*:*:*
airflow
Version:
2.8.3
CPE:
cpe:2.3:a:apache:airflow:2.8.3:-:*:*:*:*:*:*
airflow
Version:
3.0.5
CPE:
cpe:2.3:a:apache:airflow:3.0.5:-:*:*:*:*:*:*
airflow
Version:
1.5.1
CPE:
cpe:2.3:a:apache:airflow:1.5.1:*:*:*:*:*:*:*
airflow
Version:
1.10.1
CPE:
cpe:2.3:a:apache:airflow:1.10.1:*:*:*:*:*:*:*
airflow
Version:
1.9.0
CPE:
cpe:2.3:a:apache:airflow:1.9.0:-:*:*:*:*:*:*
airflow
Version:
3.0.6
CPE:
cpe:2.3:a:apache:airflow:3.0.6:-:*:*:*:*:*:*
airflow
Version:
0.4.3
CPE:
cpe:2.3:a:apache:airflow:0.4.3:*:*:*:*:*:*:*
airflow
Version:
2.0.1
CPE:
cpe:2.3:a:apache:airflow:2.0.1:*:*:*:*:*:*:*
airflow
Version:
0.3.1
CPE:
cpe:2.3:a:apache:airflow:0.3.1:*:*:*:*:*:*:*
airflow
Version:
1.4.0
CPE:
cpe:2.3:a:apache:airflow:1.4.0:*:*:*:*:*:*:*
airflow
Version:
2.1.4
CPE:
cpe:2.3:a:apache:airflow:2.1.4:rc1:*:*:*:*:*:*
airflow
Version:
1.4.1
CPE:
cpe:2.3:a:apache:airflow:1.4.1:*:*:*:*:*:*:*
airflow
Version:
2.2.1
CPE:
cpe:2.3:a:apache:airflow:2.2.1:*:*:*:*:*:*:*
airflow
Version:
2.8.2
CPE:
cpe:2.3:a:apache:airflow:2.8.2:*:*:*:*:*:*:*
airflow
Version:
1.7.1.3
CPE:
cpe:2.3:a:apache:airflow:1.7.1.3:*:*:*:*:*:*:*
airflow
Version:
2.4.3
CPE:
cpe:2.3:a:apache:airflow:2.4.3:*:*:*:*:*:*:*
airflow
Version:
0.2.3
CPE:
cpe:2.3:a:apache:airflow:0.2.3:*:*:*:*:*:*:*
airflow
Version:
0.5.0
CPE:
cpe:2.3:a:apache:airflow:0.5.0:*:*:*:*:*:*:*
airflow
Version:
1.10.12
CPE:
cpe:2.3:a:apache:airflow:1.10.12:*:*:*:*:*:*:*
airflow
Version:
1.7.1
CPE:
cpe:2.3:a:apache:airflow:1.7.1:*:*:*:*:*:*:*
airflow
Version:
1.0.0
CPE:
cpe:2.3:a:apache:airflow:1.0.0:*:*:*:*:*:*:*
airflow
Version:
1.7.0
CPE:
cpe:2.3:a:apache:airflow:1.7.0:*:*:*:*:*:*:*
airflow
Version:
1.7.1.2
CPE:
cpe:2.3:a:apache:airflow:1.7.1.2:*:*:*:*:*:*:*
airflow
Version:
3.1.2
CPE:
cpe:2.3:a:apache:airflow:3.1.2:rc1:*:*:*:*:*:*
airflow
Version:
1.1.1
CPE:
cpe:2.3:a:apache:airflow:1.1.1:*:*:*:*:*:*:*
airflow
Version:
2.6.1
CPE:
cpe:2.3:a:apache:airflow:2.6.1:*:*:*:*:*:*:*
airflow
Version:
1.1.0
CPE:
cpe:2.3:a:apache:airflow:1.1.0:*:*:*:*:*:*:*
airflow
Version:
2.1.0
CPE:
cpe:2.3:a:apache:airflow:2.1.0:*:*:*:*:*:*:*
airflow
Version:
1.7.1.1
CPE:
cpe:2.3:a:apache:airflow:1.7.1.1:*:*:*:*:*:*:*
airflow
Version:
1.10.2
CPE:
cpe:2.3:a:apache:airflow:1.10.2:*:*:*:*:*:*:*
airflow
Version:
3.1.0
CPE:
cpe:2.3:a:apache:airflow:3.1.0:-:*:*:*:*:*:*
airflow
Version:
3.1.4
CPE:
cpe:2.3:a:apache:airflow:3.1.4:rc1:*:*:*:*:*:*
airflow
Version:
3.0.4
CPE:
cpe:2.3:a:apache:airflow:3.0.4:-:*:*:*:*:*:*
airflow
Version:
2.4.0
CPE:
cpe:2.3:a:apache:airflow:2.4.0:*:*:*:*:*:*:*
airflow
Version:
2.10.1
CPE:
cpe:2.3:a:apache:airflow:2.10.1:rc1:*:*:*:*:*:*
airflow
Version:
2.0.0
CPE:
cpe:2.3:a:apache:airflow:2.0.0:*:*:*:*:*:*:*
airflow
Version:
2.8.0
CPE:
cpe:2.3:a:apache:airflow:2.8.0:*:*:*:*:*:*:*
airflow
Version:
1.10.6
CPE:
cpe:2.3:a:apache:airflow:1.10.6:*:*:*:*:*:*:*
airflow
Version:
2.2.2
CPE:
cpe:2.3:a:apache:airflow:2.2.2:*:*:*:*:*:*:*
airflow
Version:
2.7.1
CPE:
cpe:2.3:a:apache:airflow:2.7.1:*:*:*:*:*:*:*
airflow
Version:
1.0.1
CPE:
cpe:2.3:a:apache:airflow:1.0.1:*:*:*:*:*:*:*
airflow
Version:
2.0.2
CPE:
cpe:2.3:a:apache:airflow:2.0.2:*:*:*:*:*:*:*
airflow
Version:
0.3
CPE:
cpe:2.3:a:apache:airflow:0.3:*:*:*:*:*:*:*
airflow
Version:
0.3.2
CPE:
cpe:2.3:a:apache:airflow:0.3.2:*:*:*:*:*:*:*
airflow
Version:
0.4.5
CPE:
cpe:2.3:a:apache:airflow:0.4.5:*:*:*:*:*:*:*
airflow
Version:
2.7.2
CPE:
cpe:2.3:a:apache:airflow:2.7.2:*:*:*:*:*:*:*
airflow
Version:
2.5.0
CPE:
cpe:2.3:a:apache:airflow:2.5.0:*:*:*:*:*:*:*
airflow
Version:
2.7.3
CPE:
cpe:2.3:a:apache:airflow:2.7.3:*:*:*:*:*:*:*
airflow
Version:
1.10.7
CPE:
cpe:2.3:a:apache:airflow:1.10.7:*:*:*:*:*:*:*
airflow
Version:
1.5.2
CPE:
cpe:2.3:a:apache:airflow:1.5.2:*:*:*:*:*:*:*
airflow
Version:
2.6.0
CPE:
cpe:2.3:a:apache:airflow:2.6.0:-:*:*:*:*:*:*
airflow
Version:
2.2.5
CPE:
cpe:2.3:a:apache:airflow:2.2.5:*:*:*:*:*:*:*
airflow
Version:
2.9.3
CPE:
cpe:2.3:a:apache:airflow:2.9.3:-:*:*:*:*:*:*
airflow
Version:
1.10.8
CPE:
cpe:2.3:a:apache:airflow:1.10.8:*:*:*:*:*:*:*
airflow
Version:
2.10.5
CPE:
cpe:2.3:a:apache:airflow:2.10.5:rc1:*:*:*:*:*:*
airflow
Version:
1.6.1
CPE:
cpe:2.3:a:apache:airflow:1.6.1:*:*:*:*:*:*:*
airflow
Version:
0.4.2
CPE:
cpe:2.3:a:apache:airflow:0.4.2:*:*:*:*:*:*:*
airflow
Version:
2.1.3
CPE:
cpe:2.3:a:apache:airflow:2.1.3:*:*:*:*:*:*:*
airflow
Version:
2.9.0
CPE:
cpe:2.3:a:apache:airflow:2.9.0:-:*:*:*:*:*:*
airflow
Version:
2.6.3
CPE:
cpe:2.3:a:apache:airflow:2.6.3:*:*:*:*:*:*:*
airflow
Version:
1.10.0
CPE:
cpe:2.3:a:apache:airflow:1.10.0:*:*:*:*:*:*:*
airflow
Version:
2.9.2
CPE:
cpe:2.3:a:apache:airflow:2.9.2:-:*:*:*:*:*:*
airflow
Version:
2.9.1
CPE:
cpe:2.3:a:apache:airflow:2.9.1:-:*:*:*:*:*:*
airflow
Version:
2.1.1
CPE:
cpe:2.3:a:apache:airflow:2.1.1:*:*:*:*:*:*:*
airflow
Version:
0.2.1
CPE:
cpe:2.3:a:apache:airflow:0.2.1:*:*:*:*:*:*:*
airflow
Version:
2.10.0
CPE:
cpe:2.3:a:apache:airflow:2.10.0:-:*:*:*:*:*:*
airflow
Version:
3.0.1
CPE:
cpe:2.3:a:apache:airflow:3.0.1:-:*:*:*:*:*:*
airflow
Version:
1.3.0
CPE:
cpe:2.3:a:apache:airflow:1.3.0:*:*:*:*:*:*:*
airflow
Version:
2.3.1
CPE:
cpe:2.3:a:apache:airflow:2.3.1:*:*:*:*:*:*:*
airflow
Version:
2.6.2
CPE:
cpe:2.3:a:apache:airflow:2.6.2:*:*:*:*:*:*:*
airflow
Version:
0.4.1
CPE:
cpe:2.3:a:apache:airflow:0.4.1:*:*:*:*:*:*:*
airflow
Version:
1.8.2
CPE:
cpe:2.3:a:apache:airflow:1.8.2:*:*:*:*:*:*:*
airflow
Version:
1.6.2
CPE:
cpe:2.3:a:apache:airflow:1.6.2:*:*:*:*:*:*:*
This vulnerability affects 111 software configuration(s). Ensure you patch all affected systems.

Severity Details

6.5
out of 10.0
Medium

Weakness Type (CWE)

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Description
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Exploit Likelihood
High
Typical Severity
Medium
Abstraction Level
Class

Key Information

Published Date
April 15, 2026