CVE-2026-41018

ADVISORY - github

Summary

The Elasticsearch logging provider, when configured with a host URL that embeds credentials (for example https://user:password@server.example.com:9200), wrote the full host URL — including the embedded credentials — into task logs. Any user with task-log read permission could harvest the backend credentials. Users are advised to upgrade to apache-airflow-providers-elasticsearch 6.5.3 or later and, as a defense-in-depth measure, configure the backend credentials via a secret backend rather than embedding them in the [elasticsearch] host URL.

EPSS Score: 0.00051 (0.164)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Insertion of Sensitive Information into Log File

ADVISORY - github

Insertion of Sensitive Information into Log File


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in