Medium severity5.4NVD Advisory· Published Aug 12, 2026· Updated Sep 16, 2026
CVE-2026-59242
CVE-2026-59242
Description
Apache Airflow's XCom GET /api/v2/{...}/xcomEntries/{key}?deserialize=true endpoint passed a string-literal payload through BaseXCom.deserialize_value without the _check_forbidden_xcom_keys guard, allowing an authenticated API user with XCom write-and-read access to instantiate arbitrary airflow.* classes on the API server (CWE-502). An authenticated user who can write an XCom value and then read it back with deserialize=true triggers the unsafe instantiation. Users are advised to upgrade to apache-airflow 3.3.1 or later, which rejects reserved XCom serialization keys submitted as JSON string literals.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/apache/airflow/pull/69378nvdIssue TrackingPatch
- www.openwall.com/lists/oss-security/2026/08/12/6nvdMailing ListThird Party Advisory
- lists.apache.org/thread/dm0520yhh4mn7qknyoh45r2w6c5qg2mgnvdMailing ListVendor Advisory
News mentions
1- Apache Projects Hit by 25 Vulnerabilities in Coordinated August 2026 DisclosureVypr Intelligence · Aug 15, 2026