
Apache Airflow Providers CVE-2026-43826: OpenSearch task-log handler leaks credentials embedded in the host URL https://www.openwall.com/lists/oss-security/2026/05/10/2 CVE-2026-41018: Elasticsearch task-log handlers leak credentials embedded in the host URL https://www.openwall.com/lists/oss-security/2026/05/10/3
Post summary
Apache Airflow providers CVE‑2026‑43826 and CVE‑2026‑41018 expose task‑log credentials via URLs for OpenSearch and Elasticsearch; the disclosure notes the issue but lacks mitigation or exploitation details.


