← العودة للجدول
CVE-2026-42359
CVE-2026-42359 — A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{k
📅 2026-06-01
🔴 Critical 🔥 No NVD Exploit Web

📋 الوصف الكامل

A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a Dag to set XCom entries under reserved key names (e.g. `return_value`) that the matching POST endpoint already validated against `FORBIDDEN_XCOM_KEYS`. The endpoint also accepted serialized payload shapes the triggerer's deserializer treats

💻 الأنظمة المتأثرة

Apache HTTP Server 2.4.x

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-42359

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-42359 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←