In Apache Airflow versions before 3.1.6, the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log output. As a result, when such connections are rendered or printed to logs, proxy credentials embedded in these fields could be exposed.

Users are recommended to upgrade to 3.1.6 or later, which fixes this issue
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache airflow
Vendors & Products Apache
Apache airflow

Fri, 16 Jan 2026 11:30:00 +0000

Type Values Removed Values Added
References

Fri, 16 Jan 2026 10:30:00 +0000

Type Values Removed Values Added
Description In Apache Airflow versions before 3.1.6, the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log output. As a result, when such connections are rendered or printed to logs, proxy credentials embedded in these fields could be exposed. Users are recommended to upgrade to 3.1.6 or later, which fixes this issue
Title Apache Airflow: proxy credentials for various providers might leak in task logs
Weaknesses CWE-532
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-01-16T11:08:28.530Z

Reserved: 2025-12-23T12:02:52.278Z

Link: CVE-2025-68675

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-16T11:16:03.913

Modified: 2026-01-16T11:16:03.913

Link: CVE-2025-68675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-16T13:41:31Z

Weaknesses