{"id":"CVE-2026-41018","aliases":["GHSA-g3jr-4jrm-jvqv","PYSEC-2026-22"],"title":"Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL","summary":"Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","vendor":"apache-airflow-providers-elasticsearch","product":"apache-airflow-providers-elasticsearch","ecosystem":"pip","affected":["apache-airflow-providers-elasticsearch < 6.5.3"],"patched":["apache-airflow-providers-elasticsearch 6.5.3"],"published":"2026-05-11","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:46.914455844Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-g3jr-4jrm-jvqv","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41018"},{"url":"https://github.com/apache/airflow/pull/65349"},{"url":"https://github.com/apache/airflow/commit/f9244064016a8db45277efb0c24808e663b233f3"},{"url":"https://github.com/apache/airflow"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow-providers-elasticsearch/PYSEC-2026-22.yaml"},{"url":"https://lists.apache.org/thread/wz5l58drprmwlv6jxnq466x24jqbbhp7"},{"url":"http://www.openwall.com/lists/oss-security/2026/05/10/3"}],"tags":["osv","pip"],"epss":0.0041,"epssPercentile":0.34905,"ingestedAt":"2026-09-12T03:13:01.694Z","slug":"CVE-2026-41018","body":"## Overview\n\nThe Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:password@server.example.com:9200`), wrote the full host URL — including the embedded credentials — into task logs. Any user with task-log read permission could harvest the backend credentials. Users are advised to upgrade to `apache-airflow-providers-elasticsearch` 6.5.3 or later and, as a defense-in-depth measure, configure the backend credentials via a secret backend rather than embedding them in the `[elasticsearch] host` URL.\n\n## Affected packages\n\n- `apache-airflow-providers-elasticsearch < 6.5.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `apache-airflow-providers-elasticsearch 6.5.3`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}