CVE Database
/

CVE-2026-33858

Back to search

CVE-2026-33858

Published: Apr 13, 2026

Modified: Apr 14, 2026

PUBLISHED

Description

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which resolves this issue.

VendorProductVersions

Apache Software Foundation

Apache Airflow

affected
3.1.8 - < 3.2.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now