In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This occurred because serialization of those fields used a secrets masker instance that did not include user-registered mask_secret() patterns, so secrets were not reliably masked before truncation and display.
Users are recommended to upgrade to 3.1.6 or later, which fixes this issue
Metrics
Affected Vendors & Products
References
History
Fri, 16 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 16 Jan 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This occurred because serialization of those fields used a secrets masker instance that did not include user-registered mask_secret() patterns, so secrets were not reliably masked before truncation and display. Users are recommended to upgrade to 3.1.6 or later, which fixes this issue | |
| Title | Apache Airflow: Secrets in rendered templates could contain parts of sensitive values when truncated | |
| Weaknesses | CWE-200 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-01-16T10:09:02.658Z
Reserved: 2025-12-17T16:31:12.717Z
Link: CVE-2025-68438
No data.
Status : Received
Published: 2026-01-16T11:16:03.760
Modified: 2026-01-16T11:16:03.760
Link: CVE-2025-68438
No data.
OpenCVE Enrichment
No data.