Database/Control plane, storage & DevOps
Apache Airflow: Callback deserialization in the scheduler timeout sweep imports Dag-author-chosen modules
Impact
Rebuilding a Callback object re-runs its constructor, which imports the module named by the stored callback path. A Dag author controls a task instance's next_kwargs through the task execution API, so the module imported is theirs, and the import happens inside the scheduler process when its awaiting_input timeout sweep deserializes that value. Because SyncCallback is an Airflow class it satisfies the default allowed_deserialization_classes allow-list, so operators who hardened that setting are not covered. The sweep runs unconditionally on default configuration, and the scheduler is the process that decides what runs on which GPU node. This is a distinct gadget from CVE-2026-58076 and CVE-2026-67260 - fixing either of those does not close it.
Who can reach it
An authenticated Dag author who can set a task instance's next_kwargs via the task execution API. No special configuration and no operator action are needed; the scheduler's own timeout sweep triggers the deserialization.
What to do
Upgrade to apache-airflow 3.3.1 or later and restart the scheduler. Only 3.3.0 is affected - the class existed earlier but the scheduler sweep that reaches it did not - so deployments on 3.2.x and below need no action for this CVE. Tightening allowed_deserialization_classes is not a workaround. Control-plane restart, no node drain.
References
Related entries
- Linux VXLAN driver (CAP_NET_ADMIN check on changelink across netns): A VXLAN tunnel's `changelink()` operates acrossCVE-2026-68432 · Linux VXLAN driver (CAP_NET_ADMIN check on changelink across netns)High
- Jenkins Multijob Plugin: Groovy features skip Script Security, giving job configurers controller RCECVE-2026-70431 · Jenkins Multijob Plugin (Groovy scripting outside Script Security)High
- Jenkins Multijob Plugin: CSRF lets an attacker run code in the Jenkins controller JVMCVE-2026-70432 · Jenkins Multijob Plugin (CSRF on code-executing endpoint)High
- Linux octeontx2-af (Marvell OCTEON CN10K, LMTLINE mailbox handler): The OCTEON CN10K admin-function mailbox handlerCVE-2026-72045 · Linux octeontx2-af (Marvell OCTEON CN10K, LMTLINE mailbox handler)High
- Linux octeontx2-af (VF clobbering shared CGX PKIND state): PF and VF NIX logical functions that share a CGX MAC reuseCVE-2026-74527 · Linux octeontx2-af (VF clobbering shared CGX PKIND state)High
- SkyPilot (API server, service account role update authorization): SkyPilot never checks whether the caller is entitledCVE-2026-75481 · SkyPilot (API server, service account role update authorization)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.