Database/Control plane, storage & DevOps
Apache Airflow: JSON Variable secrets shown in cleartext in the Rendered Templates view
Impact
The secrets masker guards its redaction with an isinstance(str) check, so a Variable whose JSON value is a dict passes through unmasked when referenced via var.json in a template. Anyone with access to that task's Rendered Templates page reads the secret verbatim. Airflow is commonly the thing that launches training and ETL jobs onto a GPU fleet, and the credentials people park in JSON Variables are exactly the high-value ones: object-store keys, registry pull secrets, cluster and scheduler tokens. Disclosure is to authenticated Airflow users who may legitimately hold only DAG-read permissions, so this widens who effectively holds the fleet's credentials.
Who can reach it
An authenticated Airflow user with permission to view a task's Rendered Templates page. No special role beyond that, and no network position beyond reach of the Airflow UI.
What to do
Upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type, and restart the API/webserver and schedulers. Upgrading does not undo the exposure: rotate every secret that was stored as a JSON Variable and referenced through var.json in a rendered template, and check access logs for who could have viewed those pages. No worker node drain or reboot needed.
References
Related entries
- Apache Airflow: masker misses team-prefixed config sections, exposing team Celery broker URLs with credentialsCVE-2026-65017 · Apache Airflow (secrets masker, team-scoped config sections in multi-team mode)Medium
- Airflow Google provider: team scope dropped in Secret Manager backend, so one team resolves another's credentialsCVE-2026-68868 · Apache Airflow Google provider (Google Cloud Secret Manager secrets backend, team scoping)Medium
- Apache Airflow Yandex provider (Lockbox secrets backend, team-scope lookup): When the team-scoped lookup for aCVE-2026-68871 · Apache Airflow Yandex provider (Lockbox secrets backend, team-scope lookup)Medium
- Airflow Amazon provider: AWS secrets backends fall through to a team-agnostic lookup, leaking other teams' credentialsCVE-2026-68872 · Apache Airflow Amazon provider (SSM Parameter Store / Secrets Manager backends)Medium
- Airflow: bulk Variable and Connection endpoints write secrets to the audit log in cleartextCVE-2026-68969 · Apache Airflow (audit-log masking on bulk Variables/Connections endpoints)Medium
- Airflow Task SDK: Variables whose JSON value is a list are not masked in task logs or rendered templatesCVE-2026-68970 · Apache Airflow Task SDK (secret masking for list-valued Variables)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.