{"id":"PYSEC-2026-1128","summary":"Apache Airflow: Sensitive configuration for providers displayed when \"non-sensitive-only\" config used","details":"Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the \"configuration\" UI page when \"non-sensitive-only\" was set as \"webserver.expose_config\" configuration (The celery provider is the only community provider currently that has sensitive configurations). You should migrate to Airflow 2.9 or change your \"expose_config\" configuration to False as a workaround. This is similar, but different to  CVE-2023-46288 https://github.com/advisories/GHSA-9qqg-mh7c-chfq  which concerned API, not UI configuration page.","aliases":["BIT-airflow-2024-31869","CVE-2024-31869","GHSA-2522-mrjc-m688"],"modified":"2026-07-07T17:56:47.719774081Z","published":"2026-07-07T11:45:39.544374Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-31869"},{"type":"WEB","url":"https://github.com/apache/airflow/pull/38795"},{"type":"WEB","url":"https://github.com/apache/airflow/commit/042c2acaed7c01933d37c2f8434640ce140a4b27"},{"type":"PACKAGE","url":"https://github.com/apache/airflow"},{"type":"WEB","url":"https://lists.apache.org/thread/pz6vg7wcjk901rmsgt86h76g6kfcgtk3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/04/17/10"},{"type":"PACKAGE","url":"https://pypi.org/project/apache-airflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2522-mrjc-m688"}],"affected":[{"package":{"name":"apache-airflow","ecosystem":"PyPI","purl":"pkg:pypi/apache-airflow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.7.0"},{"fixed":"2.9.0"}]}],"versions":["2.7.0","2.7.1","2.7.1rc1","2.7.1rc2","2.7.2","2.7.2rc1","2.7.3","2.7.3rc1","2.8.0","2.8.0b1","2.8.0rc1","2.8.0rc2","2.8.0rc3","2.8.0rc4","2.8.1","2.8.1rc1","2.8.2","2.8.2rc1","2.8.2rc2","2.8.2rc3","2.8.3","2.8.3rc1","2.8.4","2.8.4rc1","2.9.0b1","2.9.0b2","2.9.0rc1","2.9.0rc2","2.9.0rc3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/apache-airflow/PYSEC-2026-1128.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}