
Apache Airflow Providers CVE-2026-43826: OpenSearch task-log handler leaks credentials embedded in the host URL https://www.openwall.com/lists/oss-security/2026/05/10/2 CVE-2026-41018: Elasticsearch task-log handlers leak credentials embedded in the host URL https://www.openwall.com/lists/oss-security/2026/05/10/3
Post summary
The notice lists CVE-2026-43826 and CVE-2026-41018 as credential leakage vulnerabilities in Apache Airflow's OpenSearch and Elasticsearch task-log handlers, with links to discussion posts but no PoC, exploit, or patch details.


