MEDIUM6.5
PYSEC-2026-2348
Apache Airflow error reporting may expose full kwargs
Quick fix
PYSEC-2026-2348 — apache-airflow: upgrade to the fixed version with the command below.
pip install --upgrade 'apache-airflow>=2.11.1'Details
When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to authenticated users who had permission to view that DAG.
The issue has been fixed in Airflow 3.1.5rc1 and 2.11.1, and users are strongly advised to upgrade to prevent potential disclosure of sensitive information.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/apache-airflow
Introduced in:
0Fixed in: 2.11.1Fix
pip install --upgrade 'apache-airflow>=2.11.1'References
- https://nvd.nist.gov/vuln/detail/CVE-2025-65995[ADVISORY]
- https://github.com/apache/airflow/pull/58252[WEB]
- https://github.com/apache/airflow/pull/61883[WEB]
- https://github.com/apache/airflow[PACKAGE]
- https://lists.apache.org/thread/1qzlrjo2wmlzs0rrgzgslj2pzkor0dr2[WEB]
- http://www.openwall.com/lists/oss-security/2025/12/12/2[WEB]
- https://pypi.org/project/apache-airflow[PACKAGE]
- https://github.com/advisories/GHSA-gfw7-2v73-69wg[ADVISORY]