
💥 Unsafe Deserialization Flaw in Apache Airflow 3.3.0 (CVE-2026-67260) A critical flaw in Apache Airflow 3.3.0’s new awaiting_input task state sweep allows DAG authors to cause arbitrary module imports, object instantiation, or Denial of Service inside the scheduler process. ⚙️ The Cause: The scheduler's 15-second sweep deserializes task next_kwargs without checking the allowed_deserialization_classes allow-list. 🛡️ Remediation: Upgrade to Apache Airflow 3.3.1 or later immediately.
Post summary
CVE‑2026‑67260 is an unsafe deserialization flaw in Apache Airflow 3.3.0 that enables arbitrary module imports and potential denial of service; the issue is resolved in version 3.3.1, so users should upgrade immediately.



