SCA: security update for apache-airflow-core (GHSA-6ffj-2wg2-w45j)

high Tenable Cloud Security Plugin ID 440713

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom
payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted,
severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the
issue. (CVE-2026-25917)

Solution

Update the apache-airflow-core library and its related packages to version 3.2.0 or later.

See Also

https://github.com/advisories/GHSA-6ffj-2wg2-w45j

Plugin Details

Severity: High

ID: 440713

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 4/22/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.96

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 8.3

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

CVSS Score Source: CVE-2026-25917

CVSS v3

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/18/2026

Vulnerability Publication Date: 4/18/2026

Reference Information

CVE: CVE-2026-25917

cwe: CWE-502