Loading HuntDB...

GHSA-c3c6-f2ww-xfr2

GitHub Security Advisory

Apache Airflow: pickle deserialization vulnerability in XComs

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "enable_xcom_pickling=False" configuration setting resulting in poisoned data after XCom deserialization. This vulnerability is considered low since it requires a DAG author to exploit it. Users are recommended to upgrade to version 2.8.1 or later, which fixes this issue.

Affected Packages

PyPI apache-airflow
Affected versions: 0 (fixed in 2.8.1rc1)

Related CVEs

Key Information

GHSA ID
GHSA-c3c6-f2ww-xfr2
Published
January 24, 2024 3:30 PM
Last Modified
February 13, 2025 7:33 PM
CVSS Score
7.5 /10
Primary Ecosystem
PyPI
Primary Package
apache-airflow
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 17, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.