
🚨 HIGH: CVE-2026-67587 in Apache Airflow 3.3.0 allows arbitrary module import via deserialization. CVSS 8.8. Upgrade to 3.3.1+ immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/XWZsAPG9T8
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author — who controls a task instance's `next_kwargs` through the task execution API — can therefore cause an arbitrary module to be imported inside the scheduler process, when the scheduler's `awaiting_input` timeout sweep deserializes that value. No non-default configuration is required; the sweep runs unconditionally. Versions before 3.3.0 are not affected: the class existed, but the scheduler sweep that reaches it did not. This is a separate code path from CVE-2026-58076 and CVE-2026-67260, which cover different gadgets reaching deserialization — applying either of those fixes does not address this one. Users are advised to upgrade to apache-airflow 3.3.1 or later.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.

🚨 HIGH: CVE-2026-67587 in Apache Airflow 3.3.0 allows arbitrary module import via deserialization. CVSS 8.8. Upgrade to 3.3.1+ immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/XWZsAPG9T8

🚨*CVE* CVE-2026-67587 Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. … https://www.cve.org/CVERecord?id=CVE-2026-67587 ----- Traducción: CVE-2026-67587 El … http://infoflow.cloud`
Post summary
The tweet announces CVE-2026-67587, providing a brief technical description of the flaw without mentioning a PoC, exploit, or patch.

CVE-2026-67587 Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. … https://www.cve.org/CVERecord?id=CVE-2026-67587
Post summary
The post explains how Apache Airflow’s Task SDK reconstructs a `Callback` object from serialized data, potentially enabling arbitrary code execution, but does not provide a PoC, exploit, patch, or evidence of active exploitation.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | apache | airflow | - | - | - |