ゆぅさん[verified]@YY20424277General
The post provides a theoretical overview of CVE‑2026‑33858 in Apache Airflow, focusing on its background, purpose, and effect, but it does not discuss exploitation, patching, or provide a PoC.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post announces a critical deserialization-based RCE in Apache Airflow (CVE‑2026‑42359), noting authenticated users can exploit the XCom PATCH API, and that version 3.2.2+ contains a fix.
Open Source Security mailing list@oss_securityDisclosure
The text announces two newly identified Apache Airflow vulnerabilities, one that logs secrets in plain text and another that permits unsafe deserialization through legacy serialization keys.
CVE@CVEnewDisclosure
A new vulnerability in DAG authors allows webserver context to execute arbitrary code via a crafted XCom payload. The CVE-2026-33858 disclosure includes technical details of the RCE flaw.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces CVE-2026-33858, describing an arbitrary code execution flaw in Apache Airflow triggered by malicious XCom payload, with no PoC or exploitation details.
CVEFind.com@CveFindComPatch
The tweet announces that upgrading to Apache Airflow 3.2.0 fixes a high‑severity CVE that allows DAG authors to execute arbitrary code, urging immediate action.