CVE-2025-66236Disclosure(apache / airflow)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch apache airflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager could make were not clear or explicit enough, even though Airflow's intentions and security model of Airflow did not suggest different assumptions. The overall security model [1], workload isolation [2], and JWT authentication details [3] are now described in more detail. Users concerned with role isolation and following the Airflow security model of Airflow are advised to upgrade to Airflow 3.2, where several security improvements have been implemented. They should also read and follow the relevant documents to make sure that their deployment is secure enough. It also clarifies that the Deployment Manager is ultimately responsible for securing your Airflow deployment. This had also been communicated via Airflow 3.2.0 Blog announcement [4]. [1] Security Model: https://airflow.apache.org/docs/apache-airflow/stable/security/jwt_token_authentication.html [2] Workload isolation: https://airflow.apache.org/docs/apache-airflow/stable/security/workload.html [3] JWT Token authentication: https://airflow.apache.org/docs/apache-airflow/stable/security/jwt_token_authentication.html [4] Airflow 3.2.0 Blog announcement: https://airflow.apache.org/blog/airflow-3.2.0/ Users are recommended to upgrade to version 3.2.0, which fixes this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-13: 3Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-13: 104-13
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2025-66236: Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI https://www.openwall.com/lists/oss-security/2026/04/13/6 CVE-2026-33858: Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API https://www.openwall.com/lists/oss-security/2026/04/13/7

    Post summary

    Two newly reported Apache Airflow CVEs are announced with brief vulnerability descriptions and links to security mailing list discussions.

    10050922
    4.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2025-66236 Security Model Clarification and Improvements in Apache Airflow 3.2.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-66236

    Post summary

    The message indicates that Apache Airflow 3.2.0 includes security improvements that address CVE‑2025‑66236, implying a patch was released, but contains no other actionable or adverse information.

    0000068
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-66236 Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details … https://www.cve.org/CVERecord?id=CVE-2025-66236

    Post summary

    The tweet references CVE-2025-66236 and notes that before Airflow 3.2.0, securing deployments required action from the Deployment Manager, indicating a disclosure of vulnerability requirements without details on exploitation or fixes.

    00000109
    57.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more