CVE-2026-67260Disclosure(apache / airflow)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache airflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the scheduler job. No non-default configuration is required: the sweep runs unconditionally every 15 seconds, and the default `allowed_deserialization_classes` setting does not cover this code path. Versions before 3.3.0 are not affected, because human-in-the-loop tasks deferred onto the triggerer instead. This is a different code path from CVE-2026-58076, which covers the same unguarded exception-node deserialization reached elsewhere — deployments that applied that fix must upgrade for this issue as well. Users are advised to upgrade to apache-airflow 3.3.1 or later.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-12); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-12: 3Mentions · 2026-09-25: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-12: 208-1209-25
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
By indicator
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    💥 Unsafe Deserialization Flaw in Apache Airflow 3.3.0 (CVE-2026-67260) A critical flaw in Apache Airflow 3.3.0’s new awaiting_input task state sweep allows DAG authors to cause arbitrary module imports, object instantiation, or Denial of Service inside the scheduler process. ⚙️ The Cause: The scheduler's 15-second sweep deserializes task next_kwargs without checking the allowed_deserialization_classes allow-list. 🛡️ Remediation: Upgrade to Apache Airflow 3.3.1 or later immediately.

    Post summary

    CVE‑2026‑67260 is an unsafe deserialization flaw in Apache Airflow 3.3.0 that enables arbitrary module imports and potential denial of service; the issue is resolved in version 3.3.1, so users should upgrade immediately.

    00010100
    288 followersView on X
  • DFIR Lab@DFIR_Lab

    🚨 HIGH: CVE-2026-67260 (CVSS 7.3) - Apache Airflow 3.3.0 deserialization flaw allows DAG authors to execute arbitrary code in scheduler or crash it. Affects v3.3.0 only. Upgrade to 3.3.1+ immediately. #CVE #PatchNow #ThreatIntel https://t.co/1aLaxsmVth

    0000030
    139 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-67260 Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task in… https://www.cve.org/CVERecord?id=CVE-2026-67260 ----- Traducción: CVE-2026-67260 Apa… http://infoflow.cloud`

    Post summary

    The post references CVE-2026-67260 in Apache Airflow, giving only a brief, incomplete description without any PoC, exploit details, patch info, or evidence of active exploitation.

    0000034
    97 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-67260 Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task in… https://www.cve.org/CVERecord?id=CVE-2026-67260

    Post summary

    The post announces a new CVE in Apache Airflow 3.3.0, detailing how the scheduler deserializes tasks during a state sweep.

    00000861
    57.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more