Critical 1 vendor · 2 advisories
CVE-2026-33264
CVE-2026-33264: critical-severity vulnerability covered by 2 tracked advisory records across Apache. Compare affected products, fixed versions and remediation.
Android app · Google Play
Monitor future Apache CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Matching phone alertsOptional email delivery
Apache2 advisories
- Critical9.8Critical [CVE-2026-33264] bug in `BaseSerialization.deserialize ` allowed unrestricted `import_string ` of attacker-controlled class pathsJul 7, 2026
- High8.8High [CVE-2026-33264 +1] Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string ` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be importedAug 12, 2026