CVE-2026-25219 is an information disclosure vulnerability in Apache Airflow affecting versions prior to 3.1.8. The vulnerability stems from improper handling of sensitive connection properties, specifically `access_key` and `connection_string` fields, which were not designated as sensitive in the secrets masker. This oversight exposed sensitive credentials used by Azure Service Bus and potentially other service providers to unauthorized viewing through the Connection UI and system logs. Any authenticated user with read permissions could observe these values, creating a credential exposure risk. The vulnerability carries a CVSS 3.1 score of 6.5 MEDIUM with a network-based attack vector requiring low complexity and low privilege user access. The primary impact is confidentiality compromise through information disclosure, with no integrity or availability impacts. The EPSS score of 0.0002 indicates minimal current exploitation prevalence, placing this in the lower tier of exploitability relative to the CVE population. There is currently no evidence of active exploitation, the vulnerability is not present on the Known Exploited Vulnerabilities catalog, and community attention appears limited given its inactive status on vulnerability tracking lists. However, the straightforward nature of the exposure—requiring only read access to observe plaintext credentials—warrants timely patching. Organizations operating Azure Service Bus connections or similar integrations storing sensitive data in these fields should prioritize upgrading to Airflow 3.1.8 or later to prevent potential credential compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 3.1.8CPE match | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* | ||
< 3.2.0CPE matchmatch criteria | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
Apr 15, 2026CVE-2026-25219: Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
Apr 15, 2026