{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-02T03:45:59.667","vulnerabilities":[{"cve":{"id":"CVE-2026-33264","sourceIdentifier":"security@apache.org","published":"2026-07-07T10:16:40.443","lastModified":"2026-07-08T19:37:10.507","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code execution on the API Server / Scheduler process, crossing the Airflow security boundary that DAG-author code must never execute in those processes. Users are advised to upgrade to `apache-airflow` 3.3.0 or later. As a defense-in-depth mitigation, deployments where DAG-author trust is limited can restrict the `[core] allowed_deserialization_classes` config to a narrow allowlist."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Airflow","defaultStatus":"unaffected","collectionURL":"https://pypi.python.org","packageName":"apache-airflow","versions":[{"version":"0","lessThan":"3.3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-07T00:00:00+00:00","id":"CVE-2026-33264","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-502"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*","versionEndExcluding":"3.3.0","matchCriteriaId":"6E334749-0D93-4319-9286-B9AC590F4698"}]}]}],"references":[{"url":"https://github.com/apache/airflow/pull/66002","source":"security@apache.org","tags":["Issue Tracking","Patch"]},{"url":"https://github.com/apache/airflow/pull/68528","source":"security@apache.org","tags":["Issue Tracking","Patch"]},{"url":"https://lists.apache.org/thread/otvdw8qt2y7xy2n5nq9xby9ky4rf5ltj","source":"security@apache.org","tags":["Vendor Advisory","Mailing List"]},{"url":"http://www.openwall.com/lists/oss-security/2026/07/07/1","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","Mailing List"]}]}}]}