CVE-2026-33264
Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize()
Beschreibung
Ein Fehler in `BaseSerialization.deserialize()` ermöglichte die uneingeschränkte Verwendung von `import_string()` für vom Angreifer kontrollierte Klassenpfade, wenn der Scheduler / API-Server ein serialisiertes DAG lädt: Ein DAG-Autor konnte einen schädlichen Trigger in ein DAG einbetten, um auf dem API-Server / Scheduler-Prozess eine Ferncodeausführung zu erreichen und die Airflow-Sicherheitsgrenze zu überschreiten, die besagt, dass der Code des DAG-Autors niemals in diesen Prozessen ausgeführt werden darf. Benutzer werden gebeten, auf `apache-airflow` 3.3.0 oder neuer zu aktualisieren. Als Verteidigung-in-Tiefe-Maßnahme können Bereitstellungen, bei denen das Vertrauen des DAG-Autors eingeschränkt ist, die Konfiguration `[core] allowed_deserialization_classes` auf eine enge Erlaubnisliste beschränken.
Metriken
Weakness-Klassen (CWE)
CWE-502Base
Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-07-08 05:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-33264","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical… → {"id":"CVE-2026-33264","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-07-07 10:16 UTC· security@apache.org
- Affected: Apache Airflow
- Description: A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code execution on the API Server / Scheduler process, crossing the Airflow security boundary that DAG-author code must never execute in those processes. Users are advised to upgrade to `apache-airflow` 3.3.0 or later. As a defense-in-depth mitigation, deployments where DAG-author trust is limited can restrict the `[core] allowed_deserialization_classes` config to a narrow allowlist.
- CWE: CWE-502
- Reference: https://github.com/apache/airflow/pull/66002
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
bitnami
airflow
Quellen & Referenzen
- http://www.openwall.com/lists/oss-security/2026/07/07/1advisory
- https://lists.apache.org/thread/otvdw8qt2y7xy2n5nq9xby9ky4rf5ltjadvisory
- https://github.com/apache/airflow/pull/66002fix
- https://github.com/apache/airflow/pull/68528fix
- https://nvd.nist.gov/vuln/detail/CVE-2026-33264web
- https://github.com/apache/airflow/commit/69b6c54ef17b048ebb0e9a656d0d9e1c99480d6bweb
- https://github.com/apache/airflow/commit/7e9bdb245e09373d91fcb7bda575ad4be63aa28dweb
- https://github.com/apache/airflowpackage
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2026-2082.yamlweb