Vulnerability Description
The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable values. An authenticated UI/API user with bulk Variable read permission could retrieve plaintext values from JSON variables whose key would otherwise trigger redaction. Affects deployments that store sensitive values in JSON-typed Airflow Variables under secret-suffixed key names. Users are advised to upgrade to `apache-airflow` 3.3.0 or later (the fix landed on `main` after 3.2.2; no 3.2.x backport).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Airflow | < 3.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/apache/airflow/pull/67495Issue TrackingPatch
- https://lists.apache.org/thread/y9kf314t6dhnv994hr11wj3tbow847ycVendor AdvisoryMailing List
- http://www.openwall.com/lists/oss-security/2026/07/07/2Third Party AdvisoryMailing List
FAQ
What is CVE-2026-48828?
CVE-2026-48828 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*...
How severe is CVE-2026-48828?
CVE-2026-48828 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-48828?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Airflow.