← Zuruck zu CVEs
CVE-2025-65995
MEDIUM6.5
Beschreibung
When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to authenticated users who had permission to view that DAG. The issue has been fixed in Airflow 3.1.4 and 2.11.1, and users are strongly advised to upgrade to prevent potential disclosure of sensitive information.
CVE Details
CVSS v3.1 Bewertung6.5
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht2/21/2026
Zuletzt geandert2/25/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
apache:airflow
Schwachen (CWE)
CWE-209
Referenzen
https://github.com/apache/airflow/pull/58252(security@apache.org)
https://github.com/apache/airflow/pull/61883(security@apache.org)
https://lists.apache.org/thread/1qzlrjo2wmlzs0rrgzgslj2pzkor0dr2(security@apache.org)
http://www.openwall.com/lists/oss-security/2025/12/12/2(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.