Apache Airflow XCom API permits unsafe deserialization through JSON string literals
Medium5.4CVE-2026-59242 · Published Aug 12, 2026 · updated Oct 2, 2026
Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to instantiate arbitrary `airflow.*` classes on the API server (CWE-502). An authenticated user who can write an XCom value and then read it back with `deserialize=true` triggers the unsafe instantiation. Users are advised to upgrade to apache-airflow 3.3.1 or later, which rejects reserved XCom serialization keys submitted as JSON string literals.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 3.3.1 | 3.3.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-502
- Also known as
- BIT-airflow-2026-59242, CVE-2026-59242, PYSEC-2026-3992
- nvd.nist.gov/vuln/detail/CVE-2026-59242
- github.com/apache/airflow/pull/69378
- github.com/apache/airflow/commit/78abd3044654d44d711eb61e475029fd1b1ccc23
- github.com/apache/airflow/commit/d08ddc0127d5be7f9b31c1f935bc4d25a897a848
- github.com/apache/airflow
- github.com/apache/airflow/releases/tag/3.3.1
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2026-3992.yaml
- lists.apache.org/thread/dm0520yhh4mn7qknyoh45r2w6c5qg2mg
- www.openwall.com/lists/oss-security/2026/08/12/6
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12 | Apache Airflow missing team context permits cross-team Dag actions and XCom reads | Medium6.5 | 3.3.1 |
| Aug 12 | Apache Airflow bulk endpoints log Variable and Connection secrets in cleartext | Medium6.5 | 3.3.1 |
| Aug 12 | Apache Airflow Task SDK fails to mask list-shaped JSON Variables | Medium6.5 | 3.3.1 |
| Aug 12 | Apache Airflow Task SDK Callback deserialization can import arbitrary modules in the scheduler | High8.8 | 3.3.1 |
| Aug 12 | Apache Airflow environment-variable secrets backend permits cross-team credential use | Medium5.4 | 3.3.1 |
| Aug 12 | Apache Airflow Config API exposes team-scoped sensitive configuration values | Medium6.5 | 3.3.1 |