Deserialization Vulnerability in Apache Airflow Affects Task State Management
CVE-2026-67260
7.3HIGH
What is CVE-2026-67260?
A vulnerability in Apache Airflow 3.3.0 allows for arbitrary module imports and object instantiation by exploiting the deserialization of task instance parameters. This occurs during a task state sweep executed by the scheduler every 15 seconds, which does not implement an allow-list for deserialized classes. As a result, attackers controlling the execution API can manipulate the process easily without any special configuration. Users are strongly advised to upgrade to versions 3.3.1 or later to mitigate this risk.
Affected Version(s)
Apache Airflow 3.3.0 < 3.3.1