CVE-2026-32690Low· 3.7▾ SunlitApache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case the variables were retrieved by the user the secrets stored as nested fields were not masked.
If developers do not store variables with sensitive values in JSON form, their projects are not affected. Otherwise upgrade to the fixed version, Apache Airflow 3.2.0.
apache-airflow-core >= 3.0.0, < 3.2.0apache-airflow >= 3.0.0, < 3.2.0Upgrade to a patched release:
apache-airflow-core 3.2.0apache-airflow 3.2.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-30912Medium· 5.3Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
CVE-2026-32228High· 7.5Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
CVE-2026-25917High· 7.2Apache Airflow allows code execution through crafted XCom payloads
CVE-2026-49298High· 8.8Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args