CVE-2026-42359: CWE-502: Deserialization of Untrusted Data in Apache Software Foundation Apache Airflow
A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a Dag to set XCom entries under reserved key names (e.g. `return_value`) that the matching POST endpoint already validated against `FORBIDDEN_XCOM_KEYS`. The endpoint also accepted serialized payload shapes the triggerer's deserializer treats as code; combined, this allowed RCE on the triggerer when the affected task next deferred. Affects deployments where untrusted users have XCom write permission on Dags that defer to the triggerer. This is a fix-bypass of CVE-2026-33858: PR #64148 added the `FORBIDDEN_XCOM_KEYS` validator only on the POST/set path; the PATCH path was not covered. Users who already upgraded for CVE-2026-33858 should additionally upgrade to `apache-airflow` 3.2.2 or later to cover the PATCH-path bypass.
AI Analysis
Technical Summary
Apache Airflow 3.2.0 contains a vulnerability (CVE-2026-42359) in its XCom PATCH endpoint that allows authenticated users with XCom write permissions to bypass key validation by setting reserved keys such as 'return_value'. The PATCH endpoint accepts serialized payloads that the deserializer treats as executable code, enabling remote code execution on the triggerer when the deferred task runs. This vulnerability is a bypass of the previous fix for CVE-2026-33858, which only applied validation on the POST/set endpoint but not on PATCH. The vulnerability affects deployments where untrusted users have XCom write permission on DAGs that defer to the triggerer. Upgrading to Apache Airflow 3.2.2 or later is necessary to mitigate this issue.
Potential Impact
Successful exploitation allows an authenticated user with XCom write permission to execute arbitrary code remotely on the triggerer process, potentially leading to full compromise of the affected Airflow deployment. This impacts environments where untrusted users have such permissions and use the vulnerable PATCH endpoint. No known exploits in the wild have been reported.
Mitigation Recommendations
Users who have upgraded to address CVE-2026-33858 must also upgrade Apache Airflow to version 3.2.2 or later to fix the PATCH endpoint bypass. Since no official vendor advisory or patch link is provided, verify the upgrade availability and details from the Apache Airflow project. Until upgraded, restrict XCom write permissions to trusted users only to reduce risk. Patch status is not yet confirmed from vendor advisory; check Apache Airflow official resources for current remediation guidance.
CVE-2026-42359: CWE-502: Deserialization of Untrusted Data in Apache Software Foundation Apache Airflow
Description
A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a Dag to set XCom entries under reserved key names (e.g. `return_value`) that the matching POST endpoint already validated against `FORBIDDEN_XCOM_KEYS`. The endpoint also accepted serialized payload shapes the triggerer's deserializer treats as code; combined, this allowed RCE on the triggerer when the affected task next deferred. Affects deployments where untrusted users have XCom write permission on Dags that defer to the triggerer. This is a fix-bypass of CVE-2026-33858: PR #64148 added the `FORBIDDEN_XCOM_KEYS` validator only on the POST/set path; the PATCH path was not covered. Users who already upgraded for CVE-2026-33858 should additionally upgrade to `apache-airflow` 3.2.2 or later to cover the PATCH-path bypass.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache Airflow 3.2.0 contains a vulnerability (CVE-2026-42359) in its XCom PATCH endpoint that allows authenticated users with XCom write permissions to bypass key validation by setting reserved keys such as 'return_value'. The PATCH endpoint accepts serialized payloads that the deserializer treats as executable code, enabling remote code execution on the triggerer when the deferred task runs. This vulnerability is a bypass of the previous fix for CVE-2026-33858, which only applied validation on the POST/set endpoint but not on PATCH. The vulnerability affects deployments where untrusted users have XCom write permission on DAGs that defer to the triggerer. Upgrading to Apache Airflow 3.2.2 or later is necessary to mitigate this issue.
Potential Impact
Successful exploitation allows an authenticated user with XCom write permission to execute arbitrary code remotely on the triggerer process, potentially leading to full compromise of the affected Airflow deployment. This impacts environments where untrusted users have such permissions and use the vulnerable PATCH endpoint. No known exploits in the wild have been reported.
Mitigation Recommendations
Users who have upgraded to address CVE-2026-33858 must also upgrade Apache Airflow to version 3.2.2 or later to fix the PATCH endpoint bypass. Since no official vendor advisory or patch link is provided, verify the upgrade availability and details from the Apache Airflow project. Until upgraded, restrict XCom write permissions to trusted users only to reduce risk. Patch status is not yet confirmed from vendor advisory; check Apache Airflow official resources for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-04-26T19:37:56.165Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a1d4e71e29bf47b50cd4983
Added to database: 6/1/2026, 9:18:41 AM
Last enriched: 6/1/2026, 9:36:04 AM
Last updated: 6/2/2026, 6:22:22 AM
Views: 34
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.