CVE-2026-54183: Apache Airflow: Airflow Variables were not masked in the UI for authenticated users

Published Aug 12, 2026
·
Updated

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a deeply-nested value was shown unmasked in the Variables UI. The exposure is limited to the UI: any authenticated user who can see the Variable in the UI can already read its full value through the Variables REST API, so this does not disclose data the user could not otherwise obtain — the masking is a shoulder-surfing defense for the UI, not an access-control boundary.

This is an incomplete-fix follow-up to CVE-2026-42358, whose fix made only the dictionary walk unbounded; lists, tuples, and sets beyond the depth limit remained unmasked in the UI. Deployments that applied the CVE-2026-42358 fix should also upgrade to address this residual case. Upgrade to apache-airflow 3.3.1 or later.

Affected Software

1 affected component
Apache Apache Airflow<3.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade apache-airflow to a version that resolves this vulnerability.

    Fixed in 3.3.1

Event History

Aug 12, 2026
CVE Published
via MITRE·03:34 PM
Data Sourced
via MITRE·03:34 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-54183?

The severity of CVE-2026-54183 is rated as 5, indicating a medium risk associated with information disclosure.

2

How do I fix CVE-2026-54183?

To fix CVE-2026-54183, update to the latest version of Apache Airflow that addresses this vulnerability.

3

Who is affected by CVE-2026-54183?

Authenticated users of Apache Airflow who access variables with sensitive data stored in deeply nested structures are affected by CVE-2026-54183.

4

What type of vulnerability is CVE-2026-54183?

CVE-2026-54183 is classified as an information leakage vulnerability due to improper masking of sensitive data.

5

When was CVE-2026-54183 published?

CVE-2026-54183 was published on August 12, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203