CVE-2025-27555Disclosure(apache / airflow)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables appeared in the audit log and were stored unencrypted in the Airflow database. While this risk is limited to users with audit log access, it is recommended to upgrade to Airflow 2.11.1 or a later version, which addresses this issue. Users who previously used the CLI to set connections should manually delete entries with those connection sensitive values from the log table. This is similar but not the same issue as CVE-2024-50378

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-23); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-23: 2Mentions · 2026-02-24: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-24: 102-2302-24
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-232
Disclosure1General1
2026-02-241
Disclosure1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2025-27555: Apache Airflow: Connection Secrets not masked in UI when connections are added via CLI https://www.openwall.com/lists/oss-security/2026/02/23/2 allows authenticated users with audit log access to see sensitive values in audit logs which they should not see

    Post summary

    Apache Airflow CVE-2025-27555 exposes unmasked connection secrets in audit logs for users with audit log access, allowing them to view sensitive values added via the CLI.

    10010421
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-27555 Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not … https://www.cve.org/CVERecord?id=CVE-2025-27555

    Post summary

    The post announces that Airflow versions before 2.11.1 contain an information‑disclosure flaw allowing authenticated users with audit log access to view sensitive values.

    00000108
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-27555 CVE-2025-27555 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-27555

    Post summary

    Only the CVE identifier and a generic vulnerability details URL are provided, offering no technical or operational context.

    0000038
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more