GHSA-fcmm-42r9-mmmmMediumCVSS 5.4
Apache Airflow XCom API permits unsafe deserialization through JSON string literals
🔗 CVE IDs covered (1)
📋 Description
Apache Airflow's XCom GET /api/v2/{...}/xcomEntries/{key}?deserialize=true endpoint passed a string-literal payload through BaseXCom.deserialize_value without the _check_forbidden_xcom_keys guard, allowing an authenticated API user with XCom write-and-read access to instantiate arbitrary airflow.* classes on the API server (CWE-502). An authenticated user who can write an XCom value and then read it back with deserialize=true triggers the unsafe instantiation. Users are advised to upgrade to apache-airflow 3.3.1 or later, which rejects reserved XCom serialization keys submitted as JSON string literals.
🎯 Affected products1
- pip/apache-airflow:< 3.3.1
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-59242
- https://github.com/apache/airflow/pull/69378
- https://lists.apache.org/thread/dm0520yhh4mn7qknyoh45r2w6c5qg2mg
- http://www.openwall.com/lists/oss-security/2026/08/12/6
- https://github.com/apache/airflow/commit/78abd3044654d44d711eb61e475029fd1b1ccc23
- https://github.com/apache/airflow/commit/d08ddc0127d5be7f9b31c1f935bc4d25a897a848
- https://github.com/apache/airflow/releases/tag/3.3.1
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2026-3992.yaml
- https://github.com/advisories/GHSA-fcmm-42r9-mmmm