Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6ffj-2wg2-w45j | Apache Airflow allows code execution through crafted XCom payloads |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 22 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 21 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:* |
Mon, 20 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Sat, 18 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow |
|
| Vendors & Products |
Apache
Apache airflow |
Sat, 18 Apr 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 18 Apr 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. | |
| Title | Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5) | |
| Weaknesses | CWE-502 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-04-22T13:58:49.807Z
Reserved: 2026-02-09T11:43:28.920Z
Link: CVE-2026-25917
Updated: 2026-04-18T06:28:53.080Z
Status : Modified
Published: 2026-04-18T07:16:09.347
Modified: 2026-04-22T14:16:36.140
Link: CVE-2026-25917
No data.
OpenCVE Enrichment
Updated: 2026-04-20T18:45:14Z
Github GHSA