CVE-2026-33858Disclosure(apache / airflow)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache airflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which resolves this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-04-13); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-13: 4Mentions · 2026-06-01: 1Mentions · 2026-06-08: 1Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-06-01: 1Technical Details · 2026-04-13: 4Technical Details · 2026-06-01: 1Technical Details · 2026-06-08: 104-1306-0106-08
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-134
Disclosure3Patch1
2026-06-011
Disclosure1
2026-06-081
General1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2025-66236: Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI https://www.openwall.com/lists/oss-security/2026/04/13/6 CVE-2026-33858: Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API https://www.openwall.com/lists/oss-security/2026/04/13/7

    Post summary

    The text announces two newly identified Apache Airflow vulnerabilities, one that logs secrets in plain text and another that permits unsafe deserialization through legacy serialization keys.

    10050922
    4.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33858 Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since … https://www.cve.org/CVERecord?id=CVE-2026-33858

    Post summary

    A new vulnerability in DAG authors allows webserver context to execute arbitrary code via a crafted XCom payload. The CVE-2026-33858 disclosure includes technical details of the RCE flaw.

    00010126
    57.1K followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「Apache Software FoundationのApache Airflowにおける信頼できないデータのデシリアライゼーションに関する脆弱性(CVE-2026-33858)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手コンサル ▶ note メンバーシップ: https://note.com/yuusan_security/membership

    Post summary

    The post provides a theoretical overview of CVE‑2026‑33858 in Apache Airflow, focusing on its background, purpose, and effect, but it does not discuss exploitation, patching, or provide a PoC.

    0000060
    868 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Apache Airflow Deserialization RCE (CVE-2026-42359) Authenticated users with XCom write permission can exploit a deserialization flaw in the XCom PATCH API endpoint. This allows setting reserved keys (e.g. return_value), leading to remote code execution on the triggerer when deferred tasks run. This is a bypass of the previous fix for CVE-2026-33858. 👉Affected: Apache Airflow 3.2.0 , Fixed: 3.2.2+

    Post summary

    The post announces a critical deserialization-based RCE in Apache Airflow (CVE‑2026‑42359), noting authenticated users can exploit the XCom PATCH API, and that version 3.2.2+ contains a fix.

    0000080
    197 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33858 Arbitrary Code Execution in Apache Airflow via Malicious XCom Payload https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33858

    Post summary

    The post announces CVE-2026-33858, describing an arbitrary code execution flaw in Apache Airflow triggered by malicious XCom payload, with no PoC or exploitation details.

    0000040
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33858: HIGH] Important: Apache Airflow 3.2.0 resolves a security issue where Dag Authors could execute arbitrary code. Upgrade now to enhance cyber security.#cve,CVE-2026-33858,#cybersecurity https://cvefind.com/CVE-2026-33858

    Post summary

    The tweet announces that upgrading to Apache Airflow 3.2.0 fixes a high‑severity CVE that allows DAG authors to execute arbitrary code, urging immediate action.

    0000044
    620 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more