Apache Airflow Config API exposes team-scoped sensitive configuration values
Medium6.5CVE-2026-65017 · Published Aug 12, 2026 · updated Oct 2, 2026
Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access , with no prior access to the secret , could read a team-scoped Celery broker URL, including its embedded credentials, in cleartext, while the equivalent global option was correctly masked. The secrets masker matched only base section and option names and did not normalize team-prefixed sections before the sensitivity check (CWE-200). This is a distinct masker bypass from CVE-2026-48828 and CVE-2026-48892: deployments that upgraded to apache-airflow 3.3.0 to address those issues remain affected by this team-scoped variant. Users are advised to upgrade to apache-airflow 3.3.1 or later, which normalizes team-scoped sections before masking.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | >= 3.3.0, < 3.3.1 | 3.3.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- BIT-airflow-2026-65017, CVE-2026-65017, PYSEC-2026-3993
- nvd.nist.gov/vuln/detail/CVE-2026-65017
- github.com/apache/airflow/pull/70755
- github.com/apache/airflow/commit/62d37d52bf4df38b6acd3a1e73203508878f36c4
- github.com/apache/airflow/commit/d41ac7b6d213682db3ef4d21bbb33e013dde4af4
- github.com/apache/airflow
- github.com/apache/airflow/releases/tag/3.3.1
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2026-3993.yaml
- lists.apache.org/thread/kykn94kjf0tntx4wywtvjowh5bzdgf38
- www.cve.org/CVERecord?id=CVE-2026-48828
- www.cve.org/CVERecord?id=CVE-2026-48892
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | Apache Airflow missing team context permits cross-team Dag actions and XCom reads | Medium6.5 | 3.3.1 |
| Aug 12 | Apache Airflow bulk endpoints log Variable and Connection secrets in cleartext | Medium6.5 | 3.3.1 |
| Aug 12 | Apache Airflow Task SDK fails to mask list-shaped JSON Variables | Medium6.5 | 3.3.1 |
| Aug 12 | Apache Airflow Task SDK Callback deserialization can import arbitrary modules in the scheduler | High8.8 | 3.3.1 |
| Aug 12 | Apache Airflow environment-variable secrets backend permits cross-team credential use | Medium5.4 | 3.3.1 |
| Aug 12 | Apache Airflow XCom API permits unsafe deserialization through JSON string literals | Medium5.4 | 3.3.1 |