Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a team name containing an underscore, which team names are allowed to contain. When the guard did not apply, the lookup fell through to an unconditional global read that resolved the stored `AIRFLOW_CONN__<TEAM>___<ID>` variable regardless of which team asked. In m
Affected packages
- apache-airflow— before 3.3.1
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- http://www.openwall.com/lists/oss-security/2026/08/12/11
- https://lists.apache.org/thread/v4mc51dgmrc1t82mhzsngsgzo2gxsf2l
- https://github.com/apache/airflow/pull/70736
- https://github.com/apache/airflow/pull/70902
Structured record: https://osv.dev/vulnerability/PYSEC-2026-3709
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta