Severity: low 

Affected versions:

- Apache Airflow (apache-airflow) 3.1.8 before 3.2.0

Description:

Dag Authors, who normally should not be able to execute code in the webserver 
context could craft XCom payload causing the webserver to execute arbitrary 
code. Since Dag Authors are already highly trusted, severity of this issue is 
Low.


Users are recommended to upgrade to Apache Airflow 3.2.0, which resolves this 
issue.

Credit:

wooseokdotkim (finder)
Amogh Desai (remediation developer)

References:

https://github.com/apache/airflow/pull/64148
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-33858

Reply via email to