VYPR
Medium severity6.5NVD Advisory· Published Aug 12, 2026· Updated Sep 16, 2026

CVE-2026-59244

CVE-2026-59244

Description

Apache Airflow's secrets masker did not mask var.json Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an isinstance(str) guard — so a secret stored as a JSON Variable and referenced in a template via var.json was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Apache/Airflowllm-fuzzy2 versions
    >=3.3.1+ 1 more
    • (no CPE)range: >=3.3.1
    • cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*range: <3.3.1
  • osv-coords
    Range: < 3.3.1

Patches

Vulnerability mechanics

References

3

News mentions

1