Users are recommended to upgrade to 3.1.6 or later, which fixes this issue
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3qmm-r55x-hpxx | Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 16 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow |
|
| Vendors & Products |
Apache
Apache airflow |
Fri, 16 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 16 Jan 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length, sensitive values could be exposed in cleartext in the Rendered Templates UI. This occurred because serialization of those fields used a secrets masker instance that did not include user-registered mask_secret() patterns, so secrets were not reliably masked before truncation and display. Users are recommended to upgrade to 3.1.6 or later, which fixes this issue | |
| Title | Apache Airflow: Secrets in rendered templates could contain parts of sensitive values when truncated | |
| Weaknesses | CWE-200 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-01-16T16:10:02.986Z
Reserved: 2025-12-17T16:31:12.717Z
Link: CVE-2025-68438
Updated: 2026-01-16T10:09:02.658Z
Status : Undergoing Analysis
Published: 2026-01-16T11:16:03.760
Modified: 2026-01-16T16:15:54.007
Link: CVE-2025-68438
No data.
OpenCVE Enrichment
Updated: 2026-01-16T13:41:38Z
Github GHSA