Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mahammad Huseynkhanli

#38546of 53,632
7.2Total CVSS
Vulnerabilities · 1
PT-2026-33583
7.2
2026-04-17
Apache · Apache Airflow · CVE-2026-25917
**Name of the Vulnerable Software and Affected Versions** Apache Airflow versions prior to 3.2.0 **Description** Dag Authors can craft an XCom payload that allows the webserver to execute arbitrary code, bypassing the restriction that normally prevents them from executing code in the webserver context. **Recommendations** Upgrade to Apache Airflow 3.2.0.