CVE-2026-42359: CWE-502: Deserialization of Untrusted Data in Apache Software Foundation Apache Airflow
CVE-2026-42359 is a high-severity vulnerability in Apache Airflow 3.2.0 affecting the XCom PATCH endpoint. It allows an authenticated user with XCom write permission to set entries under reserved keys, bypassing existing validation. This can lead to remote code execution (RCE) when the affected task defers to the triggerer. The issue is a bypass of a previous fix (CVE-2026-33858) because the PATCH endpoint lacked the forbidden key validation present in the POST endpoint. Users who upgraded for the previous CVE must upgrade to Apache Airflow 3.2.2 or later to fully mitigate this vulnerability.
AI Analysis
Technical Summary
Apache Airflow 3.2.0 contains a deserialization vulnerability (CWE-502) in the XCom PATCH endpoint (`PATCH /api/v2/xcomEntries/{key}`) that allows authenticated users with XCom write permissions to set XCom entries using reserved keys such as `return_value`. The POST endpoint already validated against these forbidden keys, but the PATCH endpoint did not, allowing a bypass of the prior fix for CVE-2026-33858. The endpoint accepts serialized payloads that the triggerer's deserializer treats as executable code, enabling remote code execution on the triggerer when the affected task defers. This vulnerability impacts deployments where untrusted users have XCom write permissions on DAGs that defer to the triggerer. The issue is fixed in Apache Airflow 3.2.2 and later.
Potential Impact
An authenticated user with XCom write permission can bypass key validation to inject serialized payloads that lead to remote code execution on the triggerer process. This compromises confidentiality, integrity, and availability of the affected system. The vulnerability is a fix bypass of a previous vulnerability (CVE-2026-33858) and affects Apache Airflow 3.2.0. Exploitation requires authenticated access with specific permissions.
Mitigation Recommendations
Users should upgrade Apache Airflow to version 3.2.2 or later to address this vulnerability. The vendor advisory indicates that the PATCH endpoint lacked the forbidden key validation present in the POST endpoint, which was fixed in 3.2.2. There is no indication that temporary mitigations or workarounds exist. Patch status is not explicitly stated but the advisory strongly recommends upgrading to 3.2.2 or later for full remediation.
CVE-2026-42359: CWE-502: Deserialization of Untrusted Data in Apache Software Foundation Apache Airflow
Description
CVE-2026-42359 is a high-severity vulnerability in Apache Airflow 3.2.0 affecting the XCom PATCH endpoint. It allows an authenticated user with XCom write permission to set entries under reserved keys, bypassing existing validation. This can lead to remote code execution (RCE) when the affected task defers to the triggerer. The issue is a bypass of a previous fix (CVE-2026-33858) because the PATCH endpoint lacked the forbidden key validation present in the POST endpoint. Users who upgraded for the previous CVE must upgrade to Apache Airflow 3.2.2 or later to fully mitigate this vulnerability.
CVSS v3.1
Score 8.8high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache Airflow 3.2.0 contains a deserialization vulnerability (CWE-502) in the XCom PATCH endpoint (`PATCH /api/v2/xcomEntries/{key}`) that allows authenticated users with XCom write permissions to set XCom entries using reserved keys such as `return_value`. The POST endpoint already validated against these forbidden keys, but the PATCH endpoint did not, allowing a bypass of the prior fix for CVE-2026-33858. The endpoint accepts serialized payloads that the triggerer's deserializer treats as executable code, enabling remote code execution on the triggerer when the affected task defers. This vulnerability impacts deployments where untrusted users have XCom write permissions on DAGs that defer to the triggerer. The issue is fixed in Apache Airflow 3.2.2 and later.
Potential Impact
An authenticated user with XCom write permission can bypass key validation to inject serialized payloads that lead to remote code execution on the triggerer process. This compromises confidentiality, integrity, and availability of the affected system. The vulnerability is a fix bypass of a previous vulnerability (CVE-2026-33858) and affects Apache Airflow 3.2.0. Exploitation requires authenticated access with specific permissions.
Mitigation Recommendations
Users should upgrade Apache Airflow to version 3.2.2 or later to address this vulnerability. The vendor advisory indicates that the PATCH endpoint lacked the forbidden key validation present in the POST endpoint, which was fixed in 3.2.2. There is no indication that temporary mitigations or workarounds exist. Patch status is not explicitly stated but the advisory strongly recommends upgrading to 3.2.2 or later for full remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-04-26T19:37:56.165Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a1d4e71e29bf47b50cd4983
Added to database: 06/01/2026, 09:18:41 UTC
Last enriched: 07/10/2026, 09:54:00 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 374
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.