CVE-2026-41018
ADVISORY - githubSummary
The Elasticsearch logging provider, when configured with a host URL that embeds credentials (for example https://user:password@server.example.com:9200), wrote the full host URL — including the embedded credentials — into task logs. Any user with task-log read permission could harvest the backend credentials. Users are advised to upgrade to apache-airflow-providers-elasticsearch 6.5.3 or later and, as a defense-in-depth measure, configure the backend credentials via a secret backend rather than embedding them in the [elasticsearch] host URL.
EPSS Score: 0.00051 (0.164)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Insertion of Sensitive Information into Log File
ADVISORY - github
Insertion of Sensitive Information into Log File
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in