GPU VulnDB

Database/Control plane, storage & DevOps

Apache Airflow: secrets not redacted in rendered templates are visible to any authenticated UI user

CVSS 6.5CVE-2025-66388Control plane, storage & DevOpscurated

Impact

Secret values reachable through templated task fields were not redacted in the rendered-template view, so any authenticated Airflow UI user could read them regardless of whether they were authorized for that connection or variable. On a GPU fleet Airflow is commonly the thing that drives data staging, model training jobs and cluster provisioning, which means the secrets in those templates are often registry credentials, object-store keys, cloud service-account tokens or scheduler API tokens - credentials that reach well past Airflow itself. The exposure is read-only and needs a valid login, but in a multi-team Airflow any user becomes a path to another team's credentials, and the follow-on work is credential rotation rather than just a patch.

Who can reach it

Any authenticated Airflow web UI user, no special role needed, viewing the rendered-template fields of a task. Network-reachable wherever the UI is reachable.

What to do

Upgrade to Airflow 3.1.4, which the advisory names as the fix, and restart the webserver, scheduler and workers. Patching alone is not enough: assume any secret that appeared in a rendered template has been read and rotate it, then re-check which connections and variables are referenced from templated fields.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.