PYSEC-2026-23

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/apache-airflow-providers-opensearch/PYSEC-2026-23.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-23
Aliases
Published
2026-05-11T09:16:26Z
Modified
2026-06-10T17:00:05Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

The OpenSearch logging provider, when configured with a host URL that embeds credentials (for example https://user:password@server.example.com:9200), wrote the full host URL — including the embedded credentials — into task logs. Any user with task-log read permission could harvest the backend credentials. Users are advised to upgrade to apache-airflow-providers-opensearch 1.9.1 or later and, as a defense-in-depth measure, configure the backend credentials via a secret backend rather than embedding them in the [opensearch] host URL.

References

Affected packages

PyPI / apache-airflow-providers-opensearch

Package

Name
apache-airflow-providers-opensearch
View open source insights on deps.dev
Purl
pkg:pypi/apache-airflow-providers-opensearch

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.9.1

Affected versions

1.*
1.0.0rc1
1.0.0
1.1.0rc1
1.1.0
1.1.1rc1
1.1.1
1.1.2rc1
1.1.2
1.2.0rc1
1.2.0
1.2.1rc1
1.2.1
1.3.0rc1
1.3.0
1.4.0rc1
1.4.0
1.5.0rc1
1.5.0
1.6.0rc1
1.6.0rc2
1.6.0
1.6.1rc1
1.6.1
1.6.2rc1
1.6.2
1.6.3rc1
1.6.3
1.7.0rc1
1.7.0
1.7.1rc1
1.7.1
1.7.2rc1
1.7.2
1.7.3rc1
1.7.3
1.7.4rc1
1.7.4
1.7.5rc1
1.7.5
1.8.0rc1
1.8.0
1.8.1rc1
1.8.1
1.8.2rc1
1.8.2
1.8.3rc1
1.8.3
1.8.4rc1
1.8.4
1.8.5rc1
1.8.5
1.9.0rc1
1.9.0
1.9.1rc1

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/apache-airflow-providers-opensearch/PYSEC-2026-23.yaml"