Back

HIGH

Apache Airflow: Arbitrary import in custom deadline-reference deserialization

Published Jun 1, 2026

Description

Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary class paths drawn from DAG-author-controlled serialized state without an allowlist or plugin-registry gate. A DAG author whose code reaches the scheduler — the default on single-host deployments where the DAG bundle is importable from the scheduler process — could embed a custom `DeadlineReference` whose serialized form named an attacker-controlled module path, causing the scheduler to `import_string(...)` and instantiate that class with a live SQLAlchemy session attached. Affects deployments where DAG-author code is less trusted than the scheduler process. Users are advised to upgrade to `apache-airflow` 3.2.2 or later.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner apache
Published Jun 1, 2026
Updated Jun 2, 2026
Reserved May 11, 2026

CISA Vulnrichment

Updated Jun 2, 2026

NVD

Status Analyzed
Modified Jul 21, 2026

Red Hat

No data

ENISA EUVD

Assigner apache
Published Jun 1, 2026
Updated Jun 2, 2026