https://seclists.org/oss-sec/2026/q3/78: CVE-2026-48892: Apache Airflow: Config API leaks per-key sects backend kwargs - masker bypass on synthetic options
Published Jul 7, 2026
·Updated
Affected Software
1 affected component
Apache Airflow<3.3.0
Frequently Asked Questions
1
What is the severity of CVE-2026-48892?
The severity of CVE-2026-48892 is considered moderate.
2
Which versions of Apache Airflow are affected by CVE-2026-48892?
CVE-2026-48892 affects Apache Airflow versions prior to 3.3.0.
3
What is the main issue described in CVE-2026-48892?
CVE-2026-48892 describes a vulnerability in the Config API that leaks per-key secrets-backend overrides.
4
How do I fix CVE-2026-48892?
To fix CVE-2026-48892, upgrade Apache Airflow to version 3.3.0 or later.
5
Can CVE-2026-48892 affect the security of sensitive information?
Yes, CVE-2026-48892 can lead to leakage of sensitive per-key secrets, compromising security.