CVE-2026-25917
published 2026-04-18CVE-2026-25917: Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code…
PriorityP347high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.82%
53.5th percentile
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low.
Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | < 3.2.0 | 3.2.0 |
| apache_software_foundation | apache_airflow | < 3.2.0 | 3.2.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6ffj-2wg2-w45j: Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitr
ghsa_unreviewed·2026-04-18
CVE-2026-25917 CWE-502 GHSA-6ffj-2wg2-w45j: Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitr
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low.
Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.
GHSA
Apache Airflow allows code execution through crafted XCom payloads
ghsa·2026-04-18
CVE-2026-25917 [CRITICAL] CWE-502 Apache Airflow allows code execution through crafted XCom payloads
Apache Airflow allows code execution through crafted XCom payloads
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.
VulDB
Apache Airflow 3.1.5 API deserialization
vuldb·2026-04-17
CVE-2026-25917 [CRITICAL] Apache Airflow 3.1.5 API deserialization
A vulnerability identified as critical has been detected in Apache Airflow 3.1.5. This impacts an unknown function of the component API. Performing a manipulation results in deserialization.
This vulnerability is cataloged as CVE-2026-25917. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-18
Published