https://seclists.org/oss-sec/2026/q2/160: CVE-2026-32690: Apache Airflow: 3.x - Nested Variable Sect Values Bypass daction via max_depth=1
Published Apr 17, 2026
·Updated
Affected Software
1 affected component
Apache Apache Airflow>=3.0.0<3.2.0
The severity of CVE-2026-32690 is classified as low.
CVE-2026-32690 affects Apache Airflow versions 3.0.0 before 3.2.0.
To fix CVE-2026-32690, upgrade Apache Airflow to version 3.2.0 or later.
The main issue in CVE-2026-32690 is that secrets in Variables saved as JSON dictionaries were not properly redacted when retrieved.
CVE-2026-32690 can lead to exposure of sensitive data since nested fields in secrets may not be masked when accessed.