๐Ÿ” CVE Alert

CVE-2026-45360

HIGH 7.3

Apache Airflow: Arbitrary import in custom deadline-reference deserialization

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
6th

Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary class paths drawn from DAG-author-controlled serialized state without an allowlist or plugin-registry gate. A DAG author whose code reaches the scheduler โ€” the default on single-host deployments where the DAG bundle is importable from the scheduler process โ€” could embed a custom `DeadlineReference` whose serialized form named an attacker-controlled module path, causing the scheduler to `import_string(...)` and instantiate that class with a live SQLAlchemy session attached. Affects deployments where DAG-author code is less trusted than the scheduler process. Users are advised to upgrade to `apache-airflow` 3.2.2 or later.

CWE CWE-502
Vendor apache software foundation
Product apache airflow
Published Jun 1, 2026
Last Updated Jun 2, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache airflow

Be the first to know when new high vulnerabilities affecting apache software foundation apache airflow are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Airflow
0 < 3.2.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/airflow/pull/66737 lists.apache.org: https://lists.apache.org/thread/q227dghjwgfz8xsxrf2pwpz4wk43zm83 openwall.com: http://www.openwall.com/lists/oss-security/2026/05/31/12

Credits

Jarek Potiuk