- Description
- When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to authenticated users who had permission to view that DAG. The issue has been fixed in Airflow 3.1.4 and 2.11.1, and users are strongly advised to upgrade to prevent potential disclosure of sensitive information.
- Source
- security@apache.org
- NVD status
- Analyzed
- Products
- airflow
CVSS 3.1
- Type
- Secondary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
- security@apache.org
- CWE-209
- Hype score
- Not currently trending
CVE-2025-65995 When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive value… https://t.co/LUKBgsH3Yi
@CVEnew
21 Feb 2026
96 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-65995 - CRITICAL DATA PIPELINE FAILURE: Airflow Flaw PRINTS ALL Your Cloud Secrets (AWS, Azure, DB Passwords) in Plain Sight. Read the full report on - https://t.co/0SoDhkdWPO https://t.co/mbEkwxNgc0
@cyberbivash
13 Dec 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-65995 CVE-2025-65995 https://t.co/browat2wX6
@VulmonFeeds
13 Dec 2025
45 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-66388: Apache Airflow: Secrets in rendered templates not redacted properly and exposed in the UI https://t.co/UKwRTEWEPY CVE-2025-65995: Apache Airflow: Disclosure of secrets to UI via kwargs https://t.co/R2bGSTmVcZ
@oss_security
12 Dec 2025
277 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CE505571-C239-4772-828B-050B2A942D7E",
"versionEndExcluding": "2.11.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7F18236E-476E-46C1-BE7D-7DB747DC000A",
"versionEndExcluding": "3.1.4",
"versionStartIncluding": "3.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]