Remote Code Execution Vulnerability in Apache Airflow by Apache
CVE-2026-42359
Currently unrated
What is CVE-2026-42359?
A vulnerability has been identified in Apache Airflow that exploits the PATCH endpoint for XCom entries, allowing authenticated users with appropriate permissions to manipulate reserved key names. This vulnerability enables remote code execution on the task triggerer when specific payload shapes are submitted, circumventing previously established safeguards. Users who may have already addressed related issues should ensure they are using version 3.2.2 or later to fully remediate this risk. Affected deployments include scenarios where untrusted users possess XCom write permissions on Dags, emphasizing the need for vigilant access controls.
Affected Version(s)
Apache Airflow 3.2.0 < 3.2.2