VYPR
Medium severity5.4NVD Advisory· Published Aug 12, 2026· Updated Sep 16, 2026

CVE-2026-59242

CVE-2026-59242

Description

Apache Airflow's XCom GET /api/v2/{...}/xcomEntries/{key}?deserialize=true endpoint passed a string-literal payload through BaseXCom.deserialize_value without the _check_forbidden_xcom_keys guard, allowing an authenticated API user with XCom write-and-read access to instantiate arbitrary airflow.* classes on the API server (CWE-502). An authenticated user who can write an XCom value and then read it back with deserialize=true triggers the unsafe instantiation. Users are advised to upgrade to apache-airflow 3.3.1 or later, which rejects reserved XCom serialization keys submitted as JSON string literals.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Apache/Airflow2 versions
    cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*range: <3.3.1
    • (no CPE)range: before 3.3.1
  • osv-coords
    Range: < 3.3.1

Patches

Vulnerability mechanics

References

3

News mentions

1