CVE-2025-66388 Overview
CVE-2025-66388 is an information disclosure vulnerability in Apache Airflow. Authenticated users of the Airflow web UI can view secret values within rendered task templates because the secret redaction logic fails to sanitize them. The flaw exposes credentials to users who lack authorization to view them, breaking the confidentiality boundary enforced by Airflow's secrets backend. The issue is tracked under CWE-201: Insertion of Sensitive Information Into Sent Data. Apache resolved the issue in Airflow 3.1.4.
Critical Impact
Any authenticated Airflow UI user with permission to view a task's rendered templates can read secret values such as API keys, database passwords, and connection strings that should have been redacted.
Affected Products
- Apache Airflow versions prior to 3.1.4
- Deployments using Airflow's secrets backend with templated task parameters
- Multi-tenant Airflow environments where UI users have differing authorization scopes
Discovery Timeline
- 2025-12-12 - Public disclosure via OpenWall oss-security mailing list
- 2025-12-15 - CVE-2025-66388 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-66388
Vulnerability Analysis
Apache Airflow provides a secret masking mechanism that redacts sensitive values from logs and rendered templates displayed in the web UI. The mechanism replaces registered secret values with *** before content reaches the browser. This vulnerability breaks that guarantee for rendered template views.
When a task's Jinja template references a value pulled from a secrets backend or a Variable marked as sensitive, the rendered output shown in the UI includes the raw secret. Users with the can_read permission on task instances can navigate to the Rendered Template view and read the value directly. Because Airflow role-based access control typically grants template visibility broadly, low-privilege operators can access secrets scoped to production connections they do not otherwise control.
Root Cause
The redaction pipeline did not consistently apply the secrets masker to all fields serialized into the rendered template view. Values resolved at render time bypassed the masker, so the UI received plaintext content instead of the masked representation. See Apache Airflow Pull Request #58772 for the code-level fix that expands masking coverage across the rendered template code path.
Attack Vector
Exploitation requires network access to the Airflow web interface and valid authenticated credentials with permission to view task instances. No user interaction beyond navigation is required. An attacker with a limited Airflow account browses to a DAG run, opens a task instance, and selects the Rendered Template tab. Fields that reference secrets display the underlying values in plaintext. See the Apache Airflow security advisory for additional context.
Detection Methods for CVE-2025-66388
Indicators of Compromise
- Web server access logs showing repeated GET requests to /rendered-templates or /task endpoints from a single user across many DAGs
- Audit log entries in Airflow indicating enumeration of task instances outside a user's normal operational scope
- Unexpected use of exposed credentials from IP addresses or systems that do not host the affected DAG workloads
Detection Strategies
- Correlate Airflow UI access logs with the user's DAG ownership and role assignments to surface anomalous template views
- Alert on authenticated sessions that access rendered template endpoints for a large number of distinct DAGs within a short window
- Monitor secrets backends (HashiCorp Vault, AWS Secrets Manager, GCP Secret Manager) for retrieval of secrets whose corresponding downstream credentials are later used from unexpected sources
Monitoring Recommendations
- Enable Airflow audit logging and forward web server access logs to a centralized SIEM for retention and correlation
- Track authentication events and privilege changes for Airflow UI accounts, focusing on newly created or recently elevated users
- Rotate and monitor any secrets referenced by templated tasks prior to patching to detect misuse
How to Mitigate CVE-2025-66388
Immediate Actions Required
- Upgrade Apache Airflow to version 3.1.4 or later on all scheduler, webserver, and worker nodes
- Rotate every secret that may have been rendered into a task template on a vulnerable version, including connection passwords, API tokens, and Variables
- Review Airflow RBAC role assignments and remove template-viewing permissions from users who do not require them
Patch Information
Apache Airflow 3.1.4 contains the fix, delivered through Pull Request #58772. The patch extends the secrets masker to cover the rendered template serialization path so registered secret values are replaced with *** before being sent to the UI. Refer to the Apache mailing list announcement and the OpenWall oss-security notice for release coordination details.
Workarounds
- Restrict access to the Airflow web UI at the network layer using a VPN or IP allowlist until the upgrade is deployed
- Remove or tighten the can_read permission on task instances for non-privileged roles to limit exposure of the Rendered Template view
- Refactor DAGs to pull secrets at runtime inside the task body rather than referencing them in templated fields that render in the UI
# Upgrade Apache Airflow to the patched release
pip install --upgrade "apache-airflow==3.1.4"
# Verify the installed version
airflow version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
