https://seclists.org/oss-sec/2026/q2/134: CVE-2025-54550: Apache Airflow: RCE by race condition in example_xcom dag
Published Apr 15, 2026
·Updated
Affected Software
1 affected component
pypi/apache-airflow<3.2.0
Frequently Asked Questions
1
What is the severity of CVE-2025-54550?
The severity of CVE-2025-54550 is classified as low.
2
Which versions of Apache Airflow are affected by CVE-2025-54550?
CVE-2025-54550 affects Apache Airflow versions before 3.2.0.
3
How do I fix CVE-2025-54550?
To fix CVE-2025-54550, upgrade Apache Airflow to version 3.2.0 or later.
4
What exploitation method is associated with CVE-2025-54550?
CVE-2025-54550 can be exploited through a race condition in the example_xcom DAG.
5
What impact does CVE-2025-54550 have on Apache Airflow users?
CVE-2025-54550 allows UI users with access to modify XComs to exploit the application.