Severity: low 

Affected versions:

- Apache Airflow (apache-airflow) before 3.2.0

Description:

Dag Authors, who normally should not be able to execute code in the webserver 
context could craft XCom payload causing the webserver to execute arbitrary 
code. Since Dag Authors are already highly trusted, severity of this issue is 
Low.

Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.

Credit:

Mahammad Huseynkhanli (finder)
Amogh Desai (remediation developer)

References:

https://github.com/apache/airflow/pull/61641
https://airflow.apache.org/
https://www.cve.org/CVERecord?id=CVE-2026-25917

Reply via email to