Executive brief
Apache Airflow's XCom API endpoint allows authenticated users to store and retrieve cross-component task data. A vulnerability in the deserialization process allows an authenticated user with write-and-read access to cause the server to instantiate arbitrary Airflow classes, potentially leading to remote code execution or unauthorized data access. The flaw bypasses security checks by encoding malicious payloads as JSON string literals.
Technical details
The vulnerability is an unsafe deserialization issue (CWE-502) in the GET `/api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint. The `BaseXCom.deserialize_value` function processes XCom values without applying the `_check_forbidden_xcom_keys` guard when payloads are submitted as JSON string literals. The guard's validation logic only traverses dict, list, and tuple structures but does not inspect string values, allowing an attacker to submit a JSON-encoded malicious object as a string. When the endpoint deserializes with `?deserialize=true`, the string is parsed back into a dict containing reserved keys like `__classname__`, triggering arbitrary class instantiation. Exploitation requires an authenticated API user with both write and read permissions on XCom. Apache Airflow 3.3.1 and later reject reserved serialization keys even when submitted as JSON string literals, mitigating the issue.
Affected products
- Apache Airflow before 3.3.1
Timeline
- 2026-08-12: disclosed
- 2026-07-06: patched: Fix merged in PR #69378