Apache Airflow Task SDK Callback deserialization can import arbitrary modules in the scheduler
High8.8CVE-2026-67587 · Published Aug 12, 2026 · updated Oct 2, 2026
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author , who controls a task instance's `next_kwargs` through the task execution API , can therefore cause an arbitrary module to be imported inside the scheduler process, when the scheduler's `awaiting_input` timeout sweep deserializes that value. No non-default configuration is required; the sweep runs unconditionally. Versions before 3.3.0 are not affected: the class existed, but the scheduler sweep that reaches it did not. This is a separate code path from CVE-2026-58076 and CVE-2026-67260, which cover different gadgets reaching deserialization , applying either of those fixes does not address this one. Users are advised to upgrade to apache-airflow 3.3.1 or later.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | >= 3.3.0, < 3.3.1 | 3.3.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-502
- Also known as
- BIT-airflow-2026-67587, CVE-2026-67587, PYSEC-2026-3708
- nvd.nist.gov/vuln/detail/CVE-2026-67587
- github.com/apache/airflow/pull/70704
- github.com/apache/airflow/commit/1baee0bf987eb220f15398e43572e1ed819a0130
- github.com/apache/airflow/commit/2b598cb8b0570c941633be3d16a7eb912f73180c
- github.com/apache/airflow
- github.com/apache/airflow/releases/tag/3.3.1
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2026-3708.yaml
- lists.apache.org/thread/o00ww4n69qojvsckb464dtwd2nhzy6t0
- www.cve.org/CVERecord?id=CVE-2026-58076
- www.cve.org/CVERecord?id=CVE-2026-67260
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | Apache Airflow missing team context permits cross-team Dag actions and XCom reads | Medium6.5 | 3.3.1 |
| Aug 12 | Apache Airflow bulk endpoints log Variable and Connection secrets in cleartext | Medium6.5 | 3.3.1 |
| Aug 12 | Apache Airflow Task SDK fails to mask list-shaped JSON Variables | Medium6.5 | 3.3.1 |
| Aug 12 | Apache Airflow environment-variable secrets backend permits cross-team credential use | Medium5.4 | 3.3.1 |
| Aug 12 | Apache Airflow Config API exposes team-scoped sensitive configuration values | Medium6.5 | 3.3.1 |
| Aug 12 | Apache Airflow XCom API permits unsafe deserialization through JSON string literals | Medium5.4 | 3.3.1 |