Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32690

18
FAUCET Score

OVERVIEW CVE-2026-32690 affects Apache Airflow and involves improper redaction of sensitive data stored within JSON-formatted variables. When users retrieve variables containing nested secrets in JSON dictionary format, these sensitive fields fail to be properly masked, potentially exposing confidential information. Organizations using Airflow are only impacted if they store sensitive values in JSON variable structures; those utilizing alternative storage methods remain unaffected. Apache Airflow version 3.2.0 contains the implemented fix. SEVERITY The vulnerability carries a low CVSS score of 3.7, with a network-based attack vector requiring high complexity and no user interaction to exploit. The attack requires no privileges and poses a limited confidentiality impact while maintaining integrity and availability. The EPSS score of 0.000760000 indicates minimal prevalence relative to the broader CVE landscape, ranking higher than approximately 0.23 percent of all published vulnerabilities. EXPLOITATION STATUS There is no evidence of active exploitation, as the vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on exploit tracking lists. No publicly available exploit code has been identified. The relatively low risk score of 28.0 on the FAUCET scale and negligible EPSS metrics suggest minimal community attention and low likelihood of weaponization. Organizations should prioritize patching based on their specific use of JSON variables rather than urgency driven by active threats.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, < 3.2.0CPE match
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.7LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.42%
Probability of exploitation in next 30 days
EPSS Percentile
34.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0042 is in the 22nd percentile among its peer group of 1,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

pippatch availablevia ghsa
Product: apache-airflow-coreFixed in: 3.2.0
pippatch availablevia ghsa
Product: apache-airflowFixed in: 3.2.0
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

pipGHSA-w9r4-94fj-xp69low

Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries

Apr 18, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10949.htmlLOW

CVE-2026-32690: Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1

Apr 17, 2026

References

openwall.com / lists/oss-security/2026/04/17/6
Mailing ListThird Party Advisory
github.com / apache/airflow/pull/63480
Issue Tracking
lists.apache.org / thread/7rnzxofntcznqxnhsmjvvlvygwph7rn5
Mailing ListVendor Advisory