---
id: CVE-2025-66388
title: "A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redacted,\_potentially exposing secrets to users without the appropriate authorization.\n\nUsers …"
summary: "A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redacted,\_potentially exposing secrets to users without the appropriate authorization.\n\nUsers …"
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-201
vendor: apache
product: airflow
affected:
  - 'airflow >= 3.1.0, < 3.1.4'
patched:
  - airflow 3.1.4
published: '2025-12-15'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66388'
references:
  - url: 'https://github.com/apache/airflow/pull/58772'
    label: security@apache.org
  - url: 'https://lists.apache.org/thread/mv9hzsx8grjf7gdlkxwppnpbtogtls2g'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2025/12/12/1'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00479
epssPercentile: 0.39293
ingestedAt: '2026-10-07T19:44:15.685Z'
---

## Overview

A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secrets not being properly redacted, potentially exposing secrets to users without the appropriate authorization.

Users are recommended to upgrade to version 3.1.4, which fixes this issue.

## Affected

- `airflow >= 3.1.0, < 3.1.4`

## Remediation

Upgrade past the affected range:

- `airflow 3.1.4`
