Apache Airflow DAG Parsing Error Kwargs Disclosure Vulnerability

Vulnerability

A vulnerability exists in Apache Airflow versions prior to 3.1.4, where the error-reporting UI could inadvertently expose full keyword arguments (kwargs) passed to operators in the event of a Directed Acyclic Graph (DAG) parsing failure. If these kwargs included sensitive information, such as secrets, this data could be visible in the UI tracebacks to authenticated users with permission to view the DAG.

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information, such as secrets, to authenticated users via the Airflow UI.

Remediation

Users are advised to upgrade to Apache Airflow versions 3.1.4 or 2.11.1.

Added: Feb 21, 2026, 3:19 AM
Updated: Feb 21, 2026, 3:19 AM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
4.8
remediation
7.7
relevance
3.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.