In Apache Airflow versions before 3.1.6, the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log output. As a result, when such connections are rendered or printed to logs, proxy credentials embedded in these fields could be exposed.

Users are recommended to upgrade to 3.1.6 or later, which fixes this issue
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-7c2f-r6gc-h92h Apache Airflow proxy credentials for various providers might leak in task logs
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 16 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache airflow
Vendors & Products Apache
Apache airflow

Fri, 16 Jan 2026 11:30:00 +0000

Type Values Removed Values Added
References

Fri, 16 Jan 2026 10:30:00 +0000

Type Values Removed Values Added
Description In Apache Airflow versions before 3.1.6, the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log output. As a result, when such connections are rendered or printed to logs, proxy credentials embedded in these fields could be exposed. Users are recommended to upgrade to 3.1.6 or later, which fixes this issue
Title Apache Airflow: proxy credentials for various providers might leak in task logs
Weaknesses CWE-532
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-01-16T16:06:50.034Z

Reserved: 2025-12-23T12:02:52.278Z

Link: CVE-2025-68675

cve-icon Vulnrichment

Updated: 2026-01-16T11:08:28.530Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-01-16T11:16:03.913

Modified: 2026-01-16T16:15:54.167

Link: CVE-2025-68675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-16T13:41:31Z

Weaknesses