MEDIUM

CVE-2025-27555

Apache Airflow: Connection Secrets not masked in UI when Connection are added via Airflow cli

CVSS v3

6.5

MEDIUM

EPSS Score

0.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

none

SSVC status

Description

Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables appeared in the audit log and were stored unencrypted in the Airflow database. While this risk is limited to users with audit log access, it is recommended to upgrade to Airflow 2.11.1 or a later version, which addresses this issue. Users w

Technical details

CVSS v3 Vector
3.1
Published
2/24/2026
Last Modified
3/11/2026

Frequently asked questions

What is CVE-2025-27555?

Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables appeared in the audit log and were stored unencrypted in the Airflow database. While this risk is limited to users with audit log access, it is recommended to upgrade to Airflow 2.11.1 or a later version, which addresses this issue. Users w

Is CVE-2025-27555 actively exploited?

Active exploitation of CVE-2025-27555 has not been confirmed. The EPSS score is 0.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2025-27555?

CVE-2025-27555 has a CVSS v3 base score of 6.5 (MEDIUM severity), with vector string 3.1.

Is CVE-2025-27555 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.