THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-49487 (MEDIUM 6.5) — In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, any authenticated user with DAG-scoped task-

[NVD] CVE-2026-49487 (MEDIUM 6.5) — In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, any authenticated user with DAG-scoped task-

lownvdPublished 2026-07-07

CVE-2026-49487 CVSS: 6.5 MEDIUM Published: 2026-07-07T10:16:41.723

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, any authenticated user with DAG-scoped task-instance read access for that DAG could read that se

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-49487