Arbitrary Class Instantiation Vulnerability in Apache Airflow
CVE-2026-59242
5.4MEDIUM
What is CVE-2026-59242?
The vulnerability in Apache Airflow's XCom API endpoint allows an authenticated user with write-and-read access to manipulate the XCom storage. By sending a potentially malicious input through the deserialization process without proper safeguards, attackers can instantiate any class within the airflow.* namespace. To mitigate this risk, users should upgrade to version 3.3.1 or later, which implements crucial checks against the usage of reserved XCom serialization keys.
Affected Version(s)
Apache Airflow 0 < 3.3.1