PYSEC-2026-1143
Dashboard / Vulnerabilities / PYSEC-2026-1143
PYSEC-2026-1143
Summary: Apache Airflow CNCF Kubernetes Provider: KubernetesPodOperator RCE via connection configuration
Details: Arbitrary code execution in Apache Airflow CNCF Kubernetes provider version 5.0.0 allows user to change xcom sidecar image and resources via Airflow connection. In order to exploit this weakness, a user would already need elevated permissions (Op or Admin) to change the connection object in this manner. Operators should upgrade to provider version 7.0.0 which has removed the vulnerability.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-33234, https://github.com/apache/airflow, https://lists.apache.org/thread/n1vpgl6h2qsdm52o9m2tx1oo86tl4gnq, https://pypi.org/project/apache-airflow-providers-cncf-kubernetes, https://github.com/advisories/GHSA-2rx4-9f5h-9gjf
Affected packages
Package
Name: apache-airflow-providers-cncf-kubernetes
Purl: pkg:pypi/apache-airflow-providers-cncf-kubernetes
Affected ranges
Type: ECOSYSTEM
Events:
