Executive brief
Apache Airflow is an open-source platform used to schedule and monitor complex workflows. A security flaw in its data exchange component (XCom) allows authorized users to bypass safety checks and inject malicious data. If exploited, this could allow an attacker to take control of the server and execute unauthorized commands, potentially leading to data theft or service disruption.
Technical details
A deserialization of untrusted data vulnerability (CWE-502) exists in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}`. While the corresponding POST endpoint correctly validates payloads against `FORBIDDEN_XCOM_KEYS`, the PATCH endpoint lacks this validation, allowing a bypass of previous fixes (CVE-2026-33858). An authenticated attacker with XCom write permissions can set reserved key names (like `return_value`) with serialized payloads that the triggerer's deserializer interprets as code. This results in remote code execution (RCE) on the triggerer component when the affected task next defers. The issue is resolved in version 3.2.2.
Affected products
- Apache Software Foundation Apache Airflow >= 3.2.0, < 3.2.2
Timeline
- 2026-04-27: other: Fix pull request submitted
- 2026-05-07: patched: Fix merged into main branch
- 2026-06-01: disclosed: Initial advisory publication
- 2026-07-09: advisory: GitHub Advisory reviewed and updated