CVE-2026-48828

CVE-2026-48828: Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key

Vendor Apache Software Foundation
Product Apache Airflow
Weakness CWE-200 · Info exposure
Published July 7, 2026
Last update July 7, 2026

CVSS base score

What the vulnerability does

01Description

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable values. An authenticated UI/API user with bulk Variable read permission could retrieve plaintext values from JSON variables whose key would otherwise trigger redaction. Affects deployments that store sensitive values in JSON-typed Airflow Variables under secret-suffixed key names. Users are advised to upgrade to `apache-airflow` 3.3.0 or later (the fix landed on `main` after 3.2.2; no 3.2.x backport).

Key dates

02Disclosure timeline

July 7, 2026 CVE published
July 7, 2026 Record updated

Related vulnerabilities

04Related CVE