CVE-2026-48828Disclosure(apache / airflow)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable values. An authenticated UI/API user with bulk Variable read permission could retrieve plaintext values from JSON variables whose key would otherwise trigger redaction. Affects deployments that store sensitive values in JSON-typed Airflow Variables under secret-suffixed key names. Users are advised to upgrade to `apache-airflow` 3.3.0 or later (the fix landed on `main` after 3.2.2; no 3.2.x backport).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-07: 2Technical Details · 2026-07-07: 207-07
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-48828 The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on… https://www.cve.org/CVERecord?id=CVE-2026-48828 ----- Traducción: CVE-2026-48828 La … http://infoflow.cloud`

    Post summary

    The post references CVE-2026-48828, explaining that Apache Airflow’s Bulk Variables API bypasses a key‑based redaction check, but offers no PoC, exploit code, mitigation, or evidence of active exploitation.

    0000033
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-48828 The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on… https://www.cve.org/CVERecord?id=CVE-2026-48828

    Post summary

    A disclosure of CVE‑2026‑48828 reveals that Apache Airflow’s Bulk Variables API invokes the redactor without supplying the variable key, potentially compromising data handling. No PoC, exploitation evidence, or patch information is provided.

    00000659
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more