Apache Airflow scheduler unsafely deserializes human-in-the-loop task next_kwargs
🔗 CVE IDs covered (1)
📋 Description
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new awaiting_input task state swept by the scheduler. That sweep deserializes the task instance's next_kwargs without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the scheduler job. No non-default configuration is required: the sweep runs unconditionally every 15 seconds, and the default allowed_deserialization_classes setting does not cover this code path. Versions before 3.3.0 are not affected, because human-in-the-loop tasks deferred onto the triggerer instead. This is a different code path from CVE-2026-58076, which covers the same unguarded exception-node deserialization reached elsewhere — deployments that applied that fix must upgrade for this issue as well. Users are advised to upgrade to apache-airflow 3.3.1 or later.
🎯 Affected products1
- pip/apache-airflow:>= 3.3.0, < 3.3.1
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-67260
- https://github.com/apache/airflow/pull/70685
- https://lists.apache.org/thread/vygr0fh82cjzjp5k4vtfmboxryvm3lyn
- https://www.cve.org/CVERecord?id=CVE-2026-58076
- https://github.com/apache/airflow/commit/18b622920cf0f486155075125ecdcabc752b1eca
- https://github.com/apache/airflow/commit/a1ab0653121829675ad864080d2cd9d3d1688b01
- https://github.com/apache/airflow/releases/tag/3.3.1
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2026-3707.yaml
- https://github.com/advisories/GHSA-q4c3-7575-55j2