BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2026
CVE-2026-58076High confidence

Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server

Apache Software Foundation · Apache Airflow

8.8HighCVSS 3.1
Recommended action
Within 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityHighOperational priority:High, unchanged from published severity.unchanged

Evidence used

  • No CISA KEV confirmation is currently recorded.
  • EPSS is 0.92% for the current model date.

Compensating controls

  • Validate the affected product branch and deploy the verified fixed release.
  • Restrict the affected network interface to trusted sources where business-safe.
  • Monitor vendor guidance and exploitation sources for a material change.

Verification

  1. Confirm that the asset runs Apache Software Foundation Apache Airflow and falls inside the recorded affected range.
  2. Verify the installed build against the product-specific fixed version after deployment.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 30 daysRemediation target: Within 180 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Open-source package ranges3 source-attributed ranges

These OSV and GitHub advisory ranges apply only to the named package and ecosystem. A listed fixed version is not a universal product patch or proof that an update is installed.

Ecosystem and packageAffected rangeFirst fixed versionEvidence
PyPIapache-airflowECOSYSTEM: introduced 3.3.0; fixed 3.3.13.3.1OSV record ↗aggregator derived · 2 Oct 2026
PyPIapache-airflowECOSYSTEM: introduced 3.3.0; fixed 3.3.13.3.1OSV record ↗source linked ecosystem record · 2 Oct 2026
pipapache-airflow>= 3.3.0, < 3.3.13.3.1GitHub advisory ↗github reviewed aggregator · 2 Oct 2026
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2026-57315

No EUVD known-exploited evidence

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoked -- for example `subprocess.check_output`, or `builtins.eval` on the `builtins`-prefixed variant. The code runs in the **Scheduler**, which reconstructs serialized Dags in its normal loop with no request involved, and in the **API server**, on any authenticated read of the Dag such as `GET /api/v2/dags/{dag_id}/details`. Both are components the Airflow security model states must never execute Dag-author code, and both hold the metadata database credentials and the JWT signing secret. No non-default configuration is required. This is a **different sink from CVE-2026-33264**, which covered only the trigger branch of the same deserializer: deployments that upgraded in response to that advisory are still affected through the exception branch and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later, which restricts the imported class to a subclass of `BaseException`.

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
8.8 · CVSS 3.1
Advisory evidence
No linked advisory details stored yet
Recommended actionWithin 7 days

High technical severity; prioritise exposed affected systems while verifying vendor guidance.

Patch available
01

What, why and how

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoked -- for example `subprocess.check_output`, or `builtins.eval` on the `builtins`-prefixed variant. The code runs in the **Scheduler**, which reconstructs serialized Dags in its normal loop with no request involved, and in the **API server**, on any authenticated read of the Dag such as `GET /api/v2/dags/{dag_id}/details`. Both are components the Airflow security model states must never execute Dag-author code, and both hold the metadata database credentials and the JWT signing secret. No non-default configuration is required. This is a **different sink from CVE-2026-33264**, which covered only the trigger branch of the same deserializer: deployments that upgraded in response to that advisory are still affected through the exception branch and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later, which restricts the imported class to a subclass of `BaseException`.

What

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoked -- for example `subprocess.check_output`, or `builtins.eval` on the `builtins`-prefixed variant. The code runs in the **Scheduler**, which reconstructs serialized Dags in its normal loop with no request involved, and in the **API server**, on any authenticated read of the Dag such as `GET /api/v2/dags/{dag_id}/details`. Both are components the Airflow security model states must never execute Dag-author code, and both hold the metadata database credentials and the JWT signing secret. No non-default configuration is required. This is a **different sink from CVE-2026-33264**, which covered only the trigger branch of the same deserializer: deployments that upgraded in response to that advisory are still affected through the exception branch and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later, which restricts the imported class to a subclass of `BaseException`.

Why

Attacker-influenced serialised data is reconstructed as trusted objects, which can invoke dangerous application behaviour.

How

An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

What

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoked -- for example `subprocess.check_output`, or `builtins.eval` on the `builtins`-prefixed variant. The code runs in the **Scheduler**, which reconstructs serialized Dags in its normal loop with no request involved, and in the **API server**, on any authenticated read of the Dag such as `GET /api/v2/dags/{dag_id}/details`. Both are components the Airflow security model states must never execute Dag-author code, and both hold the metadata database credentials and the JWT signing secret. No non-default configuration is required. This is a **different sink from CVE-2026-33264**, which covered only the trigger branch of the same deserializer: deployments that upgraded in response to that advisory are still affected through the exception branch and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later, which restricts the imported class to a subclass of `BaseException`.

Why

Attacker-influenced serialised data is reconstructed as trusted objects, which can invoke dangerous application behaviour.

How

An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
None recorded

No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.

Likely attack path
a network path → Deserialization of Untrusted Data → cause the confidentiality, integrity or availability impact described by the vendor
Attack surface
Network
Privileges required
Low: a basic authenticated account is required
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-502 ↗

CWE-502: Deserialization of Untrusted Data. The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRLowPrivileges required: The attacker needs basic user-level privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CHighConfidentiality impact: A successful attack can cause a major loss.IHighIntegrity impact: A successful attack can cause a major loss.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
Stolen credentials, tokens and legitimate administration functions may provide continued access without deploying a large custom toolset.
NetworkCWE-502
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

ENISA EUVD · EUVD-2026-57315Official EUVD mapping

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoked -- for example `subprocess.check_output`, or `builtins.eval` on the `builtins`-prefixed variant. The code runs in the **Scheduler**, which reconstructs serialized Dags in its normal loop with no request involved, and in the **API server**, on any authenticated read of the Dag such as `GET /api/v2/dags/{dag_id}/details`. Both are components the Airflow security model states must never execute Dag-author code, and both hold the metadata database credentials and the JWT signing secret. No non-default configuration is required. This is a **different sink from CVE-2026-33264**, which covered only the trigger branch of the same deserializer: deployments that upgraded in response to that advisory are still affected through the exception branch and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later, which restricts the imported class to a subclass of `BaseException`.

Official EUVD record ↗
BSI · German · WID-SEC-2026-2823Apache Airflow: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Apache Airflow ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen.

Official advisory ↗
Cyber Security Agency of Singapore · English · CSA-SB-20260819Security Bulletin 19 Aug 2026

The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 19 Aug 2026, published on 19 August 2026. Open the linked bulletin for the product, severity and reference information published in that issue.

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2026-028781Apache Software FoundationのApache Airflowにおける信頼できないデータのデシリアライゼーションに関する脆弱性

Apache Airflow 3.3.0では、ヒューマンインザループタスクがトリガーラーからスケジューラーによって監視される新しい `awaiting_input` タスク状態に移行されました。この変更により、タスクインスタンスの `next_kwargs` を許可リストなしで逆シリアライズするスイープが実行されます。そのため、タスク実行APIを通じてその値を制御できるDAG作成者は、スケジューラープロセス内で任意のモジュールをインポートしたり、オブジェクトをインスタンス化したり、スケジューラージョブを終了させることが可能です。非デフォルトの設定は不要で、このスイープは無条件に15秒ごとに実行されます。また、デフォルトの `allowed_deserialization_classes` 設定はこのコードパスをカバーしていません。3.3.0以前のバージョンは影響を受けません。なぜなら、ヒューマンインザループタスクはトリガーラーに遅延されていたからです。これはCVE-2026-58076とは異なるコードパスであり、そちらは保護されていない例外ノードの逆シリアライズに関するものです。その修正を適用した展開環境でも、この問題のためにアップグレードが必要となります。ユーザーにはapache-airflow 3.3.1以降へのアップグレードが推奨されます。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2026-028780Apache Software FoundationのApache Airflowにおける信頼できないデータのデシリアライゼーションに関する脆弱性

Apache AirflowのTask SDKは、シリアライズされたデータから`Callback`オブジェクトを再構築する際に、そのコンストラクタを再実行し、保存されたコールバックパスによって指定されたモジュールをインポートします。`SyncCallback`はAirflowのクラスであるため、デフォルトの`allowed_deserialization_classes`許可リストを通過し、この設定を厳しくしても効果がありません。Dagの作成者は、タスク実行APIを通じてタスクインスタンスの`next_kwargs`を制御できるため、スケジューラの`awaiting_input`タイムアウトスイープがその値をデシリアライズするときに、スケジューラプロセス内で任意のモジュールをインポートさせることが可能です。特別な非デフォルト設定は不要であり、このスイープは無条件に実行されます。バージョン3.3.0未満は影響を受けません。クラス自体は存在していましたが、それに到達するスケジューラスイープは存在しませんでした。本件は、異なるガジェットをデシリアライズに到達させるCVE-2026-58076およびCVE-2026-67260とは別のコードパスによるものであり、これらの修正を適用しても対処できません。ユーザーはapache-airflow 3.3.1以降へのアップグレードを推奨されています。

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2026-028628Apache Software FoundationのApache Airflowにおける信頼できないデータのデシリアライゼーションに関する脆弱性

Apache Airflowのシリアライズレイヤーは、シリアライズされたデータから取得したクラス名に対して`import_string()`を呼び出し、同じデータから得られた引数でインスタンス化することで例外ノードを再構築していましたが、インポート可能な対象に制限がありませんでした。オペレーターの`executor_config`はその処理経路に達するため、DAG作成者は任意の呼び出し可能オブジェクトをインポートおよび実行させる値をそこに置くことが可能でした。例えば、`subprocess.check_output`や、`builtins`をプレフィックスとした`builtins.eval`などが挙げられます。このコードは、リクエストに関係なく通常のループでシリアライズされたDAGを再構築する**スケジューラー**と、認証されたDAG読み取り時(例:`GET /api/v2/dags/{dag_id}/details`)に実行される**APIサーバー**の両方で動作します。これらはいずれもAirflowのセキュリティモデルにおいてDAG作成者のコードを絶対に実行してはならないとされるコンポーネントであり、メタデータデータベースの認証情報およびJWT署名秘密鍵を保持しています。デフォルト以外の設定は不要です。これは、同じデシリアライザのトリガーブランチのみを対象とした**CVE-2026-33264とは異なる攻撃経路である**ことから、この勧告によりアップグレードを行ったデプロイメントでも例外ブランチを通じて依然として影響を受けるため、再度のアップグレードが必須です。ユーザーには、インポートされるクラスを`BaseException`のサブクラスに制限したapache-airflow 3.3.1以降へのアップグレードを推奨します。

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
Apache Airflow: 3.0.0 < 3.3.1
Fixed
An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
Action
Review the linked authoritative reference and apply the recorded fixed release appropriate to the affected product branch.
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 12 Aug 2026 · Last source change 16 Sept 2026, 14:55 UTC · CWE-502 · Deserialization of Untrusted Data

CVE recordCVE.org · 5.2
CVSS sourceNIST NVD
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2026-57315
Product sourceCNA
Remediation sourceCVE/CNA references
CWE sourceCNA
NVD statusNVD modified after enrichment

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Affected versionsThe structured affected or fixed version information changed.
    Before
    3.0.0 < 3.3.1 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    Apache Airflow: 3.0.0 < 3.3.1 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CNA ↗
  2. Vendor guidanceAuthoritative vendor guidance changed: added patch: github.com/68511; added remediation: github.com/68511; 1 further additions.
    Before
    no authoritative guidance recorded
    After
    patch: github.com/68511 · remediation: github.com/68511 · vendor advisory: lists.apache.org/t81p688t15jozxsng8521o60nh2kfsos
    security@apache.org ↗
  3. Affected versionsThe structured affected or fixed version information changed.
    Before
    3.0.0 < 3.3.1 · Fixed: No fixed version is explicitly recorded in the structured CVE data.
    After
    3.0.0 < 3.3.1 · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CNA ↗
  4. Remediation statusRemediation status changed from Awaiting fix to Patch available.
    Before
    Awaiting fix
    After
    Patch available
    security@apache.org ↗
  5. SeveritySeverity changed from Unknown to High.
    Before
    Unknown
    After
    High
    NIST NVD ↗
  6. CVSS scoreCVSS changed from not recorded to 8.8 (CVSS 3.1).
    Before
    not recorded
    After
    8.8 (CVSS 3.1 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
    NIST NVD ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2026-58076 · cve.blacktree.nl