Количество 3
Количество 3
CVE-2026-33858
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which resolves this issue.
CVE-2026-33858
Dag Authors, who normally should not be able to execute code in the we ...
GHSA-mc4f-r875-v87w
Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-33858 Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which resolves this issue. | CVSS3: 8.8 | 1% Низкий | 4 месяца назад | |
CVE-2026-33858 Dag Authors, who normally should not be able to execute code in the we ... | CVSS3: 8.8 | 1% Низкий | 4 месяца назад | |
GHSA-mc4f-r875-v87w Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API | CVSS3: 8.8 | 1% Низкий | 4 месяца назад |
Уязвимостей на страницу