https://seclists.org/oss-sec/2026/q2/136: CVE-2026-25219: Apache Airlfow: Sensitive AzuService Bus connection string (and possibly other providers) exposed to users with view access
Published Apr 15, 2026
·Updated
Affected Software
1 affected component
Apache Apache Airflow<3.2.0
Frequently Asked Questions
1
What is the severity of CVE-2026-25219?
The severity of CVE-2026-25219 is classified as low.
2
Which versions of Apache Airflow are affected by CVE-2026-25219?
CVE-2026-25219 affects all versions of Apache Airflow before 3.2.0.
3
What vulnerabilities does CVE-2026-25219 describe?
CVE-2026-25219 describes the exposure of sensitive connection properties, specifically `access_key` and `connection_string`, to users with view access.
4
How do I fix CVE-2026-25219 in Apache Airflow?
To fix CVE-2026-25219, upgrade Apache Airflow to version 3.2.0 or later.
5
Who is affected by CVE-2026-25219?
Users with read permission in Apache Airflow can see sensitive connection details due to CVE-2026-25219.