CVE-2026-67587: CWE-502: Deserialization of Untrusted Data in Apache Software Foundation Apache Airflow
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author — who controls a task instance's `next_kwargs` through the task execution API — can therefore cause an arbitrary module to be imported inside the scheduler process, when the scheduler's `awaiting_input` timeout sweep deserializes that value. No non-default configuration is required; the sweep runs unconditionally. Versions before 3.3.0 are not affected: the class existed, but the scheduler sweep that reaches it did not. This is a separate code path from CVE-2026-58076 and CVE-2026-67260, which cover different gadgets reaching deserialization — applying either of those fixes does not address this one. Users are advised to upgrade to apache-airflow 3.3.1 or later.
AI Analysis
Technical Summary
Apache Airflow's Task SDK reconstructs a Callback object by re-running its constructor, which imports a module named by the stored callback path. The SyncCallback class passes the default allowed_deserialization_classes allow-list, which does not prevent arbitrary module imports. A DAG author controlling a task instance's next_kwargs via the task execution API can exploit this to import arbitrary modules during the scheduler's awaiting_input timeout sweep deserialization. This vulnerability affects version 3.3.0 only, as earlier versions did not have the scheduler sweep code path that triggers this. This issue is distinct from CVE-2026-58076 and CVE-2026-67260 and requires upgrading to apache-airflow 3.3.1 or later for remediation.
Potential Impact
An attacker with DAG author privileges can cause the scheduler process to import arbitrary modules, potentially leading to code execution or other unintended behavior within the scheduler context. This could undermine the integrity and security of the Airflow scheduler. No non-default configuration is required to trigger this vulnerability, making it exploitable in default setups.
Mitigation Recommendations
Users should upgrade Apache Airflow to version 3.3.1 or later, as this version addresses the vulnerability. No other configuration changes or temporary mitigations are indicated. Patch status is not explicitly confirmed in the advisory, but the recommendation to upgrade to 3.3.1 or later implies an official fix is available in those versions.
CVE-2026-67587: CWE-502: Deserialization of Untrusted Data in Apache Software Foundation Apache Airflow
Description
Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author — who controls a task instance's `next_kwargs` through the task execution API — can therefore cause an arbitrary module to be imported inside the scheduler process, when the scheduler's `awaiting_input` timeout sweep deserializes that value. No non-default configuration is required; the sweep runs unconditionally. Versions before 3.3.0 are not affected: the class existed, but the scheduler sweep that reaches it did not. This is a separate code path from CVE-2026-58076 and CVE-2026-67260, which cover different gadgets reaching deserialization — applying either of those fixes does not address this one. Users are advised to upgrade to apache-airflow 3.3.1 or later.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache Airflow's Task SDK reconstructs a Callback object by re-running its constructor, which imports a module named by the stored callback path. The SyncCallback class passes the default allowed_deserialization_classes allow-list, which does not prevent arbitrary module imports. A DAG author controlling a task instance's next_kwargs via the task execution API can exploit this to import arbitrary modules during the scheduler's awaiting_input timeout sweep deserialization. This vulnerability affects version 3.3.0 only, as earlier versions did not have the scheduler sweep code path that triggers this. This issue is distinct from CVE-2026-58076 and CVE-2026-67260 and requires upgrading to apache-airflow 3.3.1 or later for remediation.
Potential Impact
An attacker with DAG author privileges can cause the scheduler process to import arbitrary modules, potentially leading to code execution or other unintended behavior within the scheduler context. This could undermine the integrity and security of the Airflow scheduler. No non-default configuration is required to trigger this vulnerability, making it exploitable in default setups.
Mitigation Recommendations
Users should upgrade Apache Airflow to version 3.3.1 or later, as this version addresses the vulnerability. No other configuration changes or temporary mitigations are indicated. Patch status is not explicitly confirmed in the advisory, but the recommendation to upgrade to 3.3.1 or later implies an official fix is available in those versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-07-29T19:47:18.427Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7c944ebf8831d539c07f52
Added to database: 08/12/2026, 15:42:06 UTC
Last enriched: 08/12/2026, 16:01:24 UTC
Last updated: 08/13/2026, 02:01:22 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.