Back

MEDIUM

Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key

Published Jul 7, 2026

Description

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable values. An authenticated UI/API user with bulk Variable read permission could retrieve plaintext values from JSON variables whose key would otherwise trigger redaction. Affects deployments that store sensitive values in JSON-typed Airflow Variables under secret-suffixed key names. Users are advised to upgrade to `apache-airflow` 3.3.0 or later (the fix landed on `main` after 3.2.2; no 3.2.x backport).

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jul 7, 2026
Updated Sep 16, 2026
Reserved May 23, 2026
CISA Vulnrichment
Updated Jul 7, 2026
NVD
Status Analyzed
Modified Sep 16, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-563F-2439-RMQ4