CVE-2026-32690 Details
Description
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented
A vulnerability exists in Apache Airflow versions 3.0.0 prior to 3.2.0, where secrets in variables saved as JSON dictionaries were not properly redacted. When these variables were retrieved by the user, secrets stored in nested fields were not masked. This issue affects users who store sensitive values in JSON format. The vulnerability has been addressed in Apache Airflow 3.2.0.
Users are advised to upgrade to Apache Airflow version 3.2.0, which includes the necessary fix. Instructions for upgrading can be found in the Apache Airflow documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/04/17/6 | CVE | Mailing ListThird Party Advisory |
| https://github.com/apache/airflow/pull/63480 | [email protected] | Issue Tracking |
| https://lists.apache.org/thread/7rnzxofntcznqxnhsmjvvlvygwph7rn5 | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-668 | Exposure of Resource to Wrong Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache airflow | >= 3.0.0, < 3.2.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | Initial Analysis | [email protected] |
| Apr 20, 2026 | CVE Modified | CISA-ADP |
| Apr 18, 2026 | New CVE Received | [email protected] |
| Apr 18, 2026 | CVE Modified | CVE |