CVE-2026-59242

CVE-2026-59242: Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint

Vendor Apache Software Foundation
Product Apache Airflow
Weakness CWE-502 · Unsafe deserialization
Published August 12, 2026
Last update August 12, 2026

CVSS base score

What the vulnerability does

01Description

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to instantiate arbitrary `airflow.*` classes on the API server (CWE-502). An authenticated user who can write an XCom value and then read it back with `deserialize=true` triggers the unsafe instantiation. Users are advised to upgrade to apache-airflow 3.3.1 or later, which rejects reserved XCom serialization keys submitted as JSON string literals.

Key dates

02Disclosure timeline

August 12, 2026 CVE published
August 12, 2026 Record updated

Related vulnerabilities

04Related CVE