Skip to content
Apache AirflowGHSA-mc4f-r875-v87w

Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API

High8.8CVE-2026-33858 · Published Apr 13, 2026 · updated Jun 5, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
>= 3.1.8, < 3.2.03.2.0
Details and references

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which resolves this issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
BIT-airflow-2026-33858, CVE-2026-33858, PYSEC-2026-20

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Apr 13Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI
CVE-2025-66236Mediumfixed in 3.2.0
Apr 15Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
CVE-2026-25219Medium6.5fixed in 3.1.8
Apr 9Apache Airflow: JWT token still valid after logout
CVE-2025-57735Critical9.1fixed in 3.2.0
Apr 9Apache Airflow has an authorization bypass in DagRun wait endpoint
CVE-2026-34538Medium6.5fixed in 3.2.0
Apr 16Apache Airflow: RCE by race condition in example_xcom dag
CVE-2025-54550High8.1fixed in 3.2.0
Apr 16Apache Airflow: JWT token appearing in logs
CVE-2026-31987Medium7.5fixed in 3.2.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.