CVE-2026-25917Disclosure(apache / airflow)

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 1 mentions (2026-04-17); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-19: 1Technical Details · 2026-04-18: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-1704-1804-1904-2104-2204-23
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-171
General1
2026-04-181
Disclosure1
2026-04-191
Disclosure1
2026-04-211
General1
2026-04-221
Disclosure1
2026-04-231
Disclosure1
Full discourse6 posts
  • Upwind Security MDR@UpwindMDR
    General

    CVE-2026-25917 | Apache Airflow Unauthorized workflow actions can lead to broader compromise. Pipelines = high-privilege attack surface.

    Post summary

    The statement briefly references CVE‑2026‑25917 in Apache Airflow, warning that unauthorized workflow actions could lead to broader compromise, but provides no further details.

    00040140
    41 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-25917: Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5) https://www.openwall.com/lists/oss-security/2026/04/17/9 CVE-2026-40948: Apache Airflow Keycloak Provider: OAuth Login CSRF — Missing State Parameter in Keycloak Auth Manager https://www.openwall.com/lists/oss-security/2026/04/17/14

    Post summary

    The message announces new CVE disclosures for Apache Airflow and its Keycloak provider, providing technical details but no PoC code or exploitation evidence; links to mailing list discussions are provided.

    10000334
    4.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An RCE vulnerability (CVE-2026-25917) affects Apache Airflow, allowing code execution via crafted XCom payloads. Monitor for updates. #ApacheAirflow #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-25917-apache-airflow-xcom-rce

    Post summary

    CVE-2026-25917 is an RCE vulnerability in Apache Airflow that allows execution through crafted XCom payloads; the advisory notes no active exploitation or patch yet and advises monitoring for updates.

    0000064
    12 followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    【セキュリティ ニュース】「Apache Airflow」にRCE脆弱性 - 評価に大きな差(1ページ目 / 全1ページ):Security NEXT https://www.security-next.com/183712 『信頼できないデータをデシリアライズする脆弱性「CVE-2026-25917」が明らかとなったもの。「DAG Authors」が細工したXComペイロードを用いて、ウェブサーバ側で任意コードを実行することが可能となる。』

    Post summary

    The article announces CVE-2026-25917, a deserialization-based RCE flaw in Apache Airflow that lets attackers execute arbitrary code using crafted XCom payloads.

    00000833
    11.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25917 Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since … https://www.cve.org/CVERecord?id=CVE-2026-25917

    Post summary

    The post announces that DAG authors can craft an XCom payload leading to arbitrary code execution in the Airflow webserver, providing a technical view of the vulnerability but no PoC, exploit code, or patch information.

    0000054
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25917 CVE-2026-25917 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25917 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post merely repeats the CVE identifier and links to Vulmon vulnerability detail and alert pages, offering no substantive information on exploitation, patches, or technical aspects.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more