In Apache Airflow versions before 3.1.6, the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log output. As a result, when such connections are rendered or printed to logs, proxy credentials embedded in these fields could be exposed. Users are recommended to upgrade to 3.1.6 or later, which fixes this issue
History

Fri, 16 Jan 2026 11:30:00 +0000

Type Values Removed Values Added
References

Fri, 16 Jan 2026 10:30:00 +0000

Type Values Removed Values Added
Description In Apache Airflow versions before 3.1.6, the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log output. As a result, when such connections are rendered or printed to logs, proxy credentials embedded in these fields could be exposed. Users are recommended to upgrade to 3.1.6 or later, which fixes this issue
Title Apache Airflow: proxy credentials for various providers might leak in task logs
Weaknesses CWE-532
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-01-16T11:08:28.530Z

Reserved: 2025-12-23T12:02:52.278Z

Link: CVE-2025-68675

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-16T11:16:03.913

Modified: 2026-01-16T11:16:03.913

Link: CVE-2025-68675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.