CVE-2026-68970Disclosure(apache / airflow)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was returned unmasked. Any authenticated user able to read the logs or rendered templates of a task that references such a Variable could recover the values, with no special configuration required. This is the list-shaped counterpart of CVE-2026-59244, whose fix covered the dict case only, so deployments that upgraded in response to that advisory remain affected and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-312

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-12: 2Technical Details · 2026-08-12: 208-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-68970 Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and i… https://www.cve.org/CVERecord?id=CVE-2026-68970

    Post summary

    The post discloses that Apache Airflow’s Task SDK does not mask list‑typed JSON variables, leaking secrets into cleartext task logs.

    00010902
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-68970 Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and i… https://www.cve.org/CVERecord?id=CVE-2026-68970 ----- Traducción: CVE-2026-68970 Apa… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑68970, a flaw in Apache Airflow’s Task SDK that exposes secrets stored as JSON list variables in cleartext logs, highlighting an information disclosure vulnerability.

    0000031
    97 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more