---
id: CVE-2026-41018
aliases:
  - GHSA-g3jr-4jrm-jvqv
  - PYSEC-2026-22
title: >-
  Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak
  credentials embedded in the host URL
summary: >-
  Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak
  credentials embedded in the host URL
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
vendor: apache-airflow-providers-elasticsearch
product: apache-airflow-providers-elasticsearch
ecosystem: pip
affected:
  - apache-airflow-providers-elasticsearch < 6.5.3
patched:
  - apache-airflow-providers-elasticsearch 6.5.3
published: '2026-05-11'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:46.914455844Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-g3jr-4jrm-jvqv'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-41018'
  - url: 'https://github.com/apache/airflow/pull/65349'
  - url: >-
      https://github.com/apache/airflow/commit/f9244064016a8db45277efb0c24808e663b233f3
  - url: 'https://github.com/apache/airflow'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow-providers-elasticsearch/PYSEC-2026-22.yaml
  - url: 'https://lists.apache.org/thread/wz5l58drprmwlv6jxnq466x24jqbbhp7'
  - url: 'http://www.openwall.com/lists/oss-security/2026/05/10/3'
tags:
  - osv
  - pip
epss: 0.0041
epssPercentile: 0.35008
ingestedAt: '2026-09-12T03:13:01.694Z'
---

## Overview

The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:password@server.example.com:9200`), wrote the full host URL — including the embedded credentials — into task logs. Any user with task-log read permission could harvest the backend credentials. Users are advised to upgrade to `apache-airflow-providers-elasticsearch` 6.5.3 or later and, as a defense-in-depth measure, configure the backend credentials via a secret backend rather than embedding them in the `[elasticsearch] host` URL.

## Affected packages

- `apache-airflow-providers-elasticsearch < 6.5.3`

## Remediation

Upgrade to a patched release:

- `apache-airflow-providers-elasticsearch 6.5.3`
