THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-48828 (MEDIUM 6.5) — The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable

[NVD] CVE-2026-48828 (MEDIUM 6.5) — The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable

lownvdPublished 2026-07-07

CVE-2026-48828 CVSS: 6.5 MEDIUM Published: 2026-07-07T10:16:41.260

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable values. An authenticated UI/API user with bulk Varia

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-48828