Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-25219

24
FAUCET Score

CVE-2026-25219 is an information disclosure vulnerability in Apache Airflow affecting versions prior to 3.1.8. The vulnerability stems from improper handling of sensitive connection properties, specifically `access_key` and `connection_string` fields, which were not designated as sensitive in the secrets masker. This oversight exposed sensitive credentials used by Azure Service Bus and potentially other service providers to unauthorized viewing through the Connection UI and system logs. Any authenticated user with read permissions could observe these values, creating a credential exposure risk. The vulnerability carries a CVSS 3.1 score of 6.5 MEDIUM with a network-based attack vector requiring low complexity and low privilege user access. The primary impact is confidentiality compromise through information disclosure, with no integrity or availability impacts. The EPSS score of 0.0002 indicates minimal current exploitation prevalence, placing this in the lower tier of exploitability relative to the CVE population. There is currently no evidence of active exploitation, the vulnerability is not present on the Known Exploited Vulnerabilities catalog, and community attention appears limited given its inactive status on vulnerability tracking lists. However, the straightforward nature of the exposure—requiring only read access to observe plaintext credentials—warrants timely patching. Organizations operating Azure Service Bus connections or similar integrations storing sensitive data in these fields should prioritize upgrading to Airflow 3.1.8 or later to prevent potential credential compromise.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 3.1.8CPE match
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
< 3.2.0CPE matchmatch criteria
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.55%
Probability of exploitation in next 30 days
EPSS Percentile
42.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0055 is in the 53rd percentile among its peer group of 21,957 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

pippatch availablevia ghsa
Product: apache-airflowFixed in: 3.1.8
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

pipGHSA-4g48-54q2-fg7qmedium

Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

Apr 15, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10936.html

CVE-2026-25219: Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

Apr 15, 2026

References

openwall.com / lists/oss-security/2026/04/15/3
Mailing ListThird Party Advisory
github.com / apache/airflow/pull/61580
Issue Tracking
github.com / apache/airflow/pull/61582
Issue Tracking
lists.apache.org / thread/t4dlmqkn0njz4chk3g7mdgzb96y4ttqh
Mailing ListVendor Advisory