Junglewise Threat Intelligence

CVE-2023-33234: PYSEC-2026-1143 - Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration

CVE-2023-33234 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: apache-airflow-providers-cncf-kubernetes (PyPI). Vendors: Apache, PyPI.

Executive brief

Apache Airflow's CNCF Kubernetes Provider contains a vulnerability in the KubernetesPodOperator that allows arbitrary code execution. An attacker with operator or admin permissions can modify the Airflow connection configuration to inject a malicious container image, enabling them to execute arbitrary code within the Kubernetes pod. This affects workflow orchestration environments where Airflow manages container-based tasks.

Technical details

The vulnerability is an improper input validation issue (CWE-74) in the KubernetesPodOperator's handling of connection configuration. Versions 5.0.0 through 6.2.0 allow authenticated users with elevated privileges (Operator or Admin role) to modify the xcom sidecar image and resource specifications through the Airflow connection object. No user interaction or additional preconditions are required beyond the initial privilege level. An attacker can exploit this to execute arbitrary code within Kubernetes pods. The vulnerability was fixed in version 7.0.0 by removing the vulnerable configuration mechanism.

Affected products

  • Apache Airflow CNCF Kubernetes Provider 5.0.0 to 6.2.0

Timeline

  • 2023-05-30: disclosed
  • 2023-07-06: advisory
  • 2023-07-06: patched: Fixed in version 7.0.0

References

Related threats