Vulnerability Details CVE-2026-41018
The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:password@server.example.com:9200`), wrote the full host URL — including the embedded credentials — into task logs. Any user with task-log read permission could harvest the backend credentials. Users are advised to upgrade to `apache-airflow-providers-elasticsearch` 6.5.3 or later and, as a defense-in-depth measure, configure the backend credentials via a secret backend rather than embedding them in the `[elasticsearch] host` URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.3%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-41018
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:1.0.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:1.0.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:1.0.2
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:1.0.3
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:1.0.4
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:2.0.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:2.0.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:2.0.2
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:2.0.3
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:2.1.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:2.2.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:3.0.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:3.0.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:3.0.2
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:3.0.3
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:4.0.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:4.1.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:4.2.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:4.2.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:4.3.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:4.3.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:4.3.2
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:4.3.3
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:4.4.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:4.5.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:4.5.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.0.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.0.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.0.2
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.1.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.1.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.2.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.3.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.3.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.3.2
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.3.3
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.3.4
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.4.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.4.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.4.2
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.5.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.5.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.5.2
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:5.5.3
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.0.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.2.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.2.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.2.2
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.3.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.3.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.3.2
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.3.3
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.3.4
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.3.5
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.4.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.4.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.4.2
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.4.3
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.4.4
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.5.0
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.5.1
-
cpe:2.3:a:apache:apache-airflow-providers-elasticsearch:6.5.2