← Voltar à pesquisa de CVEs

CVE-2026-42358

Apache Airflow

Descrição

A bug in Apache Airflow-s Variable response masker caused nested-key redaction (triggered by secret-suffixed key names like `password`, `token`, `secret`, `api_key`) to be bypassed when the JSON value-s nesting depth exceeded the shared secrets masker-s recursion limit: the masker returned the original nested item before checking the sensitive key name. An authenticated UI/API user with Variable read permission could harvest plaintext secret values stored under sensitive keys nested deep enough to exceed the masker-s depth cap. Affects deployments that store sensitive values inside deeply-nested JSON Variables. This is a residual gap in the fix for CVE-2026-32690 (which covered shallower nesting via `max_depth=1`); the depth-limit boundary itself was not raised, so the same key-name bypass pattern reappears beyond the recursion cap. Users who already upgraded for CVE-2026-32690 should additionally upgrade to `apache-airflow` 3.2.2 or later to cover the deep-nesting path.

CVSS 6.5EPSS 0.348%Risco 0.67
Ver fonte
Publicação
2026-06-01 09:16:18
Versões afetadas
<3.2.2
Tipo
Core software
Última alteração
2026-07-21 19:10:00
Vetor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N