CVE-2025-54550: Apache Airflow: RCE by race condition in example_xcom dag

Published Apr 15, 2026
·
Updated

The example examplexcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to allow UI user who had access to modify XComs to perform arbitrary execution of code on the worker. Since the UI users are already highly trusted, this is a Low severity vulnerability.

It does not affect Airflow release - exampledags are not supposed to be enabled in production environment, however users following the example could replicate the bad pattern. Documentation of Airflow 3.2.0 contains version of the example with improved resiliance for that case.

Users who followed that pattern are advised to adjust their implementations accordingly.

Affected Software

2 affected components
Apache Apache Airflow<3.2.0
Apache Airflow<3.2.0

Event History

Apr 15, 2026
CVE Published
via MITRE·12:22 AM
Data Sourced
via MITRE·12:22 AM
DescriptionWeakness
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-54550?

CVE-2025-54550 is classified as a critical severity vulnerability that allows for remote code execution due to a race condition.

2

How do I fix CVE-2025-54550?

To fix CVE-2025-54550, upgrade Apache Airflow to a version greater than 3.2.0 to eliminate the vulnerable pattern in the example_xcom DAG.

3

What affected versions are vulnerable to CVE-2025-54550?

CVE-2025-54550 affects Apache Airflow versions up to and including 3.2.0.

4

What type of vulnerability is CVE-2025-54550?

CVE-2025-54550 is a remote code execution vulnerability caused by a race condition in the xcom feature.

5

Who is impacted by CVE-2025-54550?

Users of Apache Airflow who have access to modify XComs are at risk from CVE-2025-54550, enabling potential arbitrary code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203