Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-49487— Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs

AI Predicted 7.5 Difficulty: Easy EPSS 0.41% · P34

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProductVersion RangeStatus
Apache Software FoundationApache Airflow< 3.3.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-49487

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs
Source: CVE Program / CVE List V5
Vulnerability Description
In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, any authenticated user with DAG-scoped task-instance read access for that DAG could read that secret in clear text while the task was deferred. Users should upgrade to apache-airflow 3.3.0 or later, which masks sensitive values in trigger kwargs returned by the API.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
Apache Airflow 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Software Foundation Apache Airflow是Apache Software Foundation基金会的开源工作流调度与数据管道编排平台。 Apache Airflow 3.3.0之前版本存在信息泄露漏洞,该漏洞源于REST API任务实例详情和列表端点未对延迟任务的触发器kwargs进行掩码处理,可能导致已认证用户以明文读取敏感信息。以下版本受到影响:3.3.0之前版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Apache Software FoundationApache Airflow 0 ~ 3.3.0 -

II. Public POCs for CVE-2026-49487

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-49487

登录查看更多情报信息。

Patches & Fixes for CVE-2026-49487 (1)

Mailing List Discussions for CVE-2026-49487 (1)

Same Patch Batch · Apache Software Foundation · 2026-07-07 · 6 CVEs total

CVE-2026-33264Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerial
CVE-2026-48828Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called wit
CVE-2026-49296Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagS
CVE-2026-48891Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via tri
CVE-2026-48892Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthet

IV. Related Vulnerabilities

V. Comments for CVE-2026-49487

No comments yet


Leave a comment