https://seclists.org/oss-sec/2026/q2/119: CVE-2026-33858: Apache Airflow: Unsafe Deserialization via Legacy Serialization Keys (__type/__var) Bypass in XCom API
Published Apr 13, 2026
·Updated
Affected Software
1 affected component
Apache Apache Airflow>=3.1.8<3.2.0
Frequently Asked Questions
1
What is the severity of CVE-2026-33858?
The severity of CVE-2026-33858 is classified as low.
2
How do I fix CVE-2026-33858?
To fix CVE-2026-33858, upgrade Apache Airflow to version 3.2.0 or later.
3
What are the affected versions for CVE-2026-33858?
Affected versions for CVE-2026-33858 include Apache Airflow 3.1.8 and earlier.
4
What vulnerability does CVE-2026-33858 exploit?
CVE-2026-33858 exploits unsafe deserialization via legacy serialization keys in the XCom API.
5
Who is primarily affected by CVE-2026-33858?
Dag Authors, who should not execute code in the webserver context, are primarily affected by CVE-2026-33858.