
CVE-2025-27555: Apache Airflow: Connection Secrets not masked in UI when connections are added via CLI https://www.openwall.com/lists/oss-security/2026/02/23/2 allows authenticated users with audit log access to see sensitive values in audit logs which they should not see
Post summary
Apache Airflow CVE-2025-27555 exposes unmasked connection secrets in audit logs for users with audit log access, allowing them to view sensitive values added via the CLI.


