Insertion of Sensitive Information Into Sent Data Affecting apache-airflow-core package, versions [3.3.0, 3.3.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.39% (32nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWCORE-18748191
  • published13 Aug 2026
  • disclosed12 Aug 2026
  • creditAndrew Rukin

Introduced: 12 Aug 2026

NewCVE-2026-65017  (opens in a new tab)
CWE-201  (opens in a new tab)

How to fix?

Upgrade apache-airflow-core to version 3.3.1 or higher.

Overview

Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data in the Config API when multi-team mode is enabled and the API is exposed. An attacker can obtain sensitive team-scoped Celery broker credentials by accessing configuration-read endpoints as an authenticated Viewer, due to improper masking of secrets in team-prefixed sections.

CVSS Base Scores

version 4.0
version 3.1