https://seclists.org/oss-sec/2026/q2/118: CVE-2025-66236: Apache Airflow: Sects from Airflow config file logged in plain text in DAG run logs UI
Published Apr 13, 2026
·Updated
Affected Software
1 affected component
pypi/apache-airflow>=3.0.0<3.2.0
Frequently Asked Questions
1
What is the severity of CVE-2025-66236?
The severity of CVE-2025-66236 is classified as moderate.
2
Which versions of Apache Airflow are affected by CVE-2025-66236?
Apache Airflow versions 3.0.0 before 3.2.0 are affected by CVE-2025-66236.
3
What information is logged in plain text due to CVE-2025-66236?
CVE-2025-66236 causes sensitive sections from the Airflow config file to be logged in plain text in the DAG run logs UI.
4
How can I mitigate the risks associated with CVE-2025-66236?
To mitigate the risks of CVE-2025-66236, upgrade to Apache Airflow version 3.2.0 or later.
5
What actions should secure deployments take regarding CVE-2025-66236?
Secure deployments of Apache Airflow must ensure that the Deployment Manager addresses the security model and details outlined in CVE-2025-66236.