https://seclists.org/oss-sec/2026/q2/62: CVE-2026-34538: Apache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposu)
Published Apr 9, 2026
·Updated
Affected Software
1 affected component
Apache Apache Airflow>=3.0.0<=3.1.8
The severity of CVE-2026-34538 is classified as low.
Apache Airflow versions 3.0.0 through 3.1.8 are affected by CVE-2026-34538.
CVE-2026-34538 describes an authorization bypass in the DagRun wait endpoint that exposes XCom result values improperly to users with limited permissions.
To mitigate CVE-2026-34538, upgrade Apache Airflow to version 3.2.0 or later.
CVR-2026-34538 allows users with only DAG Run read permissions, such as the Viewer role, to access XCom result values they should not have access to.