https://seclists.org/oss-sec/2026/q3/76: CVE-2026-48828: Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - dact() called without the key
Published Jul 7, 2026
·Updated
Affected Software
1 affected component
Apache Airflow<3.3.0
Frequently Asked Questions
1
What is the severity of CVE-2026-48828?
The severity of CVE-2026-48828 is moderate.
2
Which versions of Apache Airflow are affected by CVE-2026-48828?
Apache Airflow versions prior to 3.3.0 are affected by CVE-2026-48828.
3
What does CVE-2026-48828 specifically involve?
CVE-2026-48828 involves a bypass in the Bulk Variables API that fails to properly handle secret-suffixed key names.
4
How do I mitigate CVE-2026-48828?
To mitigate CVE-2026-48828, upgrade Apache Airflow to version 3.3.0 or later.
5
What is the main risk associated with CVE-2026-48828?
The main risk is the exposure of sensitive variable values due to inadequate handling in the Bulk Variables API.