CVE-2026-32690
Low
Low
Medium
High
Critical
CVSS Score
Vulnerability Description
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked.
If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented
Severity Details
out of 10.0
Low
Weakness Type (CWE)
CWE-668
Exposure of Resource to Wrong Sphere
- Description
- The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
- Typical Severity
- Medium
- Abstraction Level
- Class
Key Information
- Published Date
- April 18, 2026
