CVE-2026-42359 Details
Description
A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a Dag to set XCom entries under reserved key names (e.g. `return_value`) that the matching POST endpoint already validated against `FORBIDDEN_XCOM_KEYS`. The endpoint also accepted serialized payload shapes the triggerer's deserializer treats as code; combined, this allowed RCE on the triggerer when the affected task next deferred. Affects deployments where untrusted users have XCom write permission on Dags that defer to the triggerer. This is a fix-bypass of CVE-2026-33858: PR #64148 added the `FORBIDDEN_XCOM_KEYS` validator only on the POST/set path; the PATCH path was not covered. Users who already upgraded for CVE-2026-33858 should additionally upgrade to `apache-airflow` 3.2.2 or later to cover the PATCH-path bypass.
A vulnerability in Apache Airflow's XCom PATCH endpoint allowed authenticated users with XCom write permission to overwrite entries under reserved key names, such as 'return_value'. This exploitation was possible because the PATCH endpoint did not enforce the same key validation as the POST endpoint, creating a bypass. Additionally, the endpoint accepted serialized payloads that could be interpreted as code, leading to remote code execution when the affected task was deferred. This issue impacts deployments where untrusted users can write to XCom on Dags that defer to them.
Users should upgrade to Apache Airflow version 3.2.2 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/apache/airflow/pull/65915 | [email protected] | Issue TrackingPatch |
| https://lists.apache.org/thread/g8dqykpf1p90tysq8tln4qtkqwb1038s | [email protected] | Mailing ListVendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-33858 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache airflow | >= 3.2.0, < 3.2.2 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| Jun 2, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | CVE Modified | [email protected] |
| Jun 1, 2026 | New CVE Received | [email protected] |