Skip to content
Apache AirflowGHSA-8r55-rv5w-6pfm

Apache Airflow exposes sensitive information in its log files

Medium6.5CVE-2025-27555 · Published Feb 24, 2026 · updated Sep 10, 2026

Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables appeared in the audit log and were stored unencrypted in the Airflow database. While this risk is limited to users with audit log access, it is recommended to upgrade to Airflow 2.11.1 or a later version, which addresses this issue. Users who previously used the CLI to set connections should manually delete entries with those connection sensitive values from the log table. This is similar but not the same issue as CVE-2024-50378

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.11.12.11.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-201, CWE-532
Also known as
BIT-airflow-2025-27555, CVE-2025-27555, PYSEC-2026-2347

More Apache Airflow advisories

All Apache Airflow

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.