Wiz Agents & Workflows are here

CVE-2025-27555
Apache Airflow vulnerability analysis and mitigation

Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables appeared in the audit log and were stored unencrypted in the Airflow database. While this risk is limited to users with audit log access, it is recommended to upgrade to Airflow 2.11.1 or a later version, which addresses this issue. Users who previously used the CLI to set connections should manually delete entries with those connection sensitive values from the log table. This is similar but not the same issue as CVE-2024-50378


SourceNVD

Related Apache Airflow vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-30911HIGH8.1
  • Apache AirflowApache Airflow
  • apache-airflow
NoYesMar 17, 2026
CVE-2026-28779HIGH7.5
  • Apache AirflowApache Airflow
  • apache-airflow
NoYesMar 17, 2026
CVE-2026-26929MEDIUM6.5
  • Apache AirflowApache Airflow
  • airflow
NoYesMar 17, 2026
CVE-2025-27555MEDIUM6.5
  • Apache AirflowApache Airflow
  • airflow-core-2
NoYesFeb 24, 2026
CVE-2026-28563MEDIUM4.3
  • Apache AirflowApache Airflow
  • apache-airflow
NoYesMar 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management