CVE-2025-65995 - CVE House
Back to Database
Status published Unknown CVE-2025-65995

Apache Airflow: Disclosure of secrets to UI via kwargs

Vulnerability Description

When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to authenticated users who had permission to view that DAG.  The issue has been fixed in Airflow 3.1.4 and 2.11.1, and users are strongly advised to upgrade to prevent potential disclosure of sensitive information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-65995

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Frieder Gottman (Cariad)
  • Jens Scheffler (Bosch)
  • Jens Scheffler (Bosch)

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Airflow
Vulnerable Versions:
3.0.0, 0

Timeline

Official Publish: February 21st, 2026
Last Modified: March 8th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)