Users are recommended to upgrade to 3.1.6 or later, which fixes this issue
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3qmm-r55x-hpxx | Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated |
Wed, 21 Jan 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* |
Fri, 16 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow |
|
| Vendors & Products |
Apache
Apache airflow |
Fri, 16 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 16 Jan 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This occurred because serialization of those fields used a secrets masker instance that did not include user-registered mask_secret() patterns, so secrets were not reliably masked before truncation and display. Users are recommended to upgrade to 3.1.6 or later, which fixes this issue | |
| Title | Apache Airflow: Secrets in rendered templates could contain parts of sensitive values when truncated | |
| Weaknesses | CWE-200 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-01-16T16:10:02.986Z
Reserved: 2025-12-17T16:31:12.717Z
Link: CVE-2025-68438
Updated: 2026-01-16T10:09:02.658Z
Status : Analyzed
Published: 2026-01-16T11:16:03.760
Modified: 2026-01-21T13:44:43.577
Link: CVE-2025-68438
No data.
OpenCVE Enrichment
Updated: 2026-01-16T13:41:38Z
Github GHSA