{"apiVersion":"1.0","identifier":"CVE-2026-59244","description":"Apache Airflow-s secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task-s Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.","publishedAt":"2026-08-12T16:17:09","lastModifiedAt":"2026-08-18T20:17:19","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59244","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","epssProbability":0.0023,"riskScore":0.66,"affectedProduct":"apache-airflow","affectedVersions":"<3.3.1","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-59244","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-59244","en":"https://www.redsauce.net/en/cves/CVE-2026-59244","fr":"https://www.redsauce.net/fr/cves/CVE-2026-59244","pt":"https://www.redsauce.net/pt/cves/CVE-2026-59244","de":"https://www.redsauce.net/de/cves/CVE-2026-59244","sk":"https://www.redsauce.net/sk/cves/CVE-2026-59244","el":"https://www.redsauce.net/el/cves/CVE-2026-59244"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-59244"}}