Apache Airflow Secrets Exposure Vulnerability in Rendered Templates

Vulnerability

A vulnerability exists in Apache Airflow versions 3.1.0 prior to 3.1.4, allowing authenticated UI users to see secret values in rendered templates. This issue arises because secrets were not adequately redacted, potentially exposing them to users without the necessary authorization.

Impact

The vulnerability could lead to unauthorized exposure of sensitive secret values to users in the UI.

Remediation

Users are advised to upgrade to Apache Airflow version 3.1.4, which addresses this vulnerability.

Added: Dec 15, 2025, 12:17 PM
Updated: Dec 15, 2025, 7:02 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
5.2
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.