CVE-2026-67587Disclosure(apache / airflow)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author — who controls a task instance's `next_kwargs` through the task execution API — can therefore cause an arbitrary module to be imported inside the scheduler process, when the scheduler's `awaiting_input` timeout sweep deserializes that value. No non-default configuration is required; the sweep runs unconditionally. Versions before 3.3.0 are not affected: the class existed, but the scheduler sweep that reaches it did not. This is a separate code path from CVE-2026-58076 and CVE-2026-67260, which cover different gadgets reaching deserialization — applying either of those fixes does not address this one. Users are advised to upgrade to apache-airflow 3.3.1 or later.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-12); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
airflow

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-12: 2Mentions · 2026-09-25: 1Technical Details · 2026-08-12: 208-1209-25
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • DFIR Lab@DFIR_Lab

    🚨 HIGH: CVE-2026-67587 in Apache Airflow 3.3.0 allows arbitrary module import via deserialization. CVSS 8.8. Upgrade to 3.3.1+ immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/XWZsAPG9T8

    0000025
    139 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-67587 Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. … https://www.cve.org/CVERecord?id=CVE-2026-67587 ----- Traducción: CVE-2026-67587 El … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-67587, providing a brief technical description of the flaw without mentioning a PoC, exploit, or patch.

    0000035
    97 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-67587 Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. … https://www.cve.org/CVERecord?id=CVE-2026-67587

    Post summary

    The post explains how Apache Airflow’s Task SDK reconstructs a `Callback` object from serialized data, potentially enabling arbitrary code execution, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    000001.1K
    57.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow---

Explore more