Remote Code Execution Vulnerability in Apache Airflow by Apache
CVE-2026-42359

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 June 2026

What is CVE-2026-42359?

A vulnerability has been identified in Apache Airflow that exploits the PATCH endpoint for XCom entries, allowing authenticated users with appropriate permissions to manipulate reserved key names. This vulnerability enables remote code execution on the task triggerer when specific payload shapes are submitted, circumventing previously established safeguards. Users who may have already addressed related issues should ensure they are using version 3.2.2 or later to fully remediate this risk. Affected deployments include scenarios where untrusted users possess XCom write permissions on Dags, emphasizing the need for vigilant access controls.

Affected Version(s)

Apache Airflow 3.2.0 < 3.2.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeff Vier (`@boinger`); Izat (Anisto Mejin) — placeholders; receipt-of-confirmation replies ask each reporter to confirm preferred credit form
Venkatraman Kumar (r3dw0lfsec), Securin
Jarek Potiuk
.