In Apache Airflow versions before 3.1.6, the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log output. As a result, when such connections are rendered or printed to logs, proxy credentials embedded in these fields could be exposed. Users are recommended to upgrade to 3.1.6 or later, which fixes this issue
History

Wed, 21 Jan 2026 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

Fri, 16 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache airflow
Vendors & Products Apache
Apache airflow

Fri, 16 Jan 2026 11:30:00 +0000

Type Values Removed Values Added
References

Fri, 16 Jan 2026 10:30:00 +0000

Type Values Removed Values Added
Description In Apache Airflow versions before 3.1.6, the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log output. As a result, when such connections are rendered or printed to logs, proxy credentials embedded in these fields could be exposed. Users are recommended to upgrade to 3.1.6 or later, which fixes this issue
Title Apache Airflow: proxy credentials for various providers might leak in task logs
Weaknesses CWE-532
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2026-01-16T10:23:25.946Z

Updated: 2026-01-16T16:06:50.034Z

Reserved: 2025-12-23T12:02:52.278Z

Link: CVE-2025-68675

cve-icon Vulnrichment

Updated: 2026-01-16T11:08:28.530Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-16T11:16:03.913

Modified: 2026-01-21T13:43:00.497

Link: CVE-2025-68675

cve-icon Redhat

No data.