Database/Control plane, storage & DevOps
Apache Airflow: secrets not redacted in rendered templates are visible to any authenticated UI user
Impact
Secret values reachable through templated task fields were not redacted in the rendered-template view, so any authenticated Airflow UI user could read them regardless of whether they were authorized for that connection or variable. On a GPU fleet Airflow is commonly the thing that drives data staging, model training jobs and cluster provisioning, which means the secrets in those templates are often registry credentials, object-store keys, cloud service-account tokens or scheduler API tokens - credentials that reach well past Airflow itself. The exposure is read-only and needs a valid login, but in a multi-team Airflow any user becomes a path to another team's credentials, and the follow-on work is credential rotation rather than just a patch.
Who can reach it
Any authenticated Airflow web UI user, no special role needed, viewing the rendered-template fields of a task. Network-reachable wherever the UI is reachable.
What to do
Upgrade to Airflow 3.1.4, which the advisory names as the fix, and restart the webserver, scheduler and workers. Patching alone is not enough: assume any secret that appeared in a rendered template has been read and rotate it, then re-check which connections and variables are referenced from templated fields.
References
Related entries
- pulp-ansible: collection remote token stored per worker leaks to an attacker-controlled remoteCVE-2026-103869 · pulp-ansible (bearer-token refresh for collection remotes)Medium
- GitLab CE/EE: malformed CSV import lets an authenticated user stall Sidekiq workersCVE-2026-1403 · GitLab CE/EE (CSV import, Sidekiq worker)Medium
- PostgreSQL pgcrypto: PGP functions emit recoverable cleartext when OpenSSL disables the cipherCVE-2026-14663 · PostgreSQL pgcrypto (pgp_sym_encrypt / pgp_pub_encrypt family)Medium
- Keycloak: authenticated user can exhaust server memory via unbounded Prometheus metric labelsCVE-2026-16100 · Keycloak (user-event Prometheus metrics)Medium
- open-iscsi iscsiuio (DHCPv6 handling): Integer underflow and out-of-bounds read in iscsiuio's DHCPv6 handlingCVE-2026-18727 · open-iscsi iscsiuio (DHCPv6 handling)Medium
- Grafana: injected timeGroup macro in a SQL query exhausts memory and kills the server processCVE-2026-19475 · Grafana SQL data sources (regex macro parsing, timeGroup injected via WHERE clause)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.