High 1 vendor · 3 advisories
CVE-2026-58076
CVE-2026-58076: high-severity vulnerability covered by 3 tracked advisory records across Apache. Compare affected products, fixed versions and remediation.
Android app · Google Play
Monitor future Apache CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Matching phone alertsOptional email delivery
Apache3 advisories
- High7.3High [CVE-2026-58076 +1] Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the schedulerAug 12, 2026
- UnratedUnknown [CVE-2026-58076 +2] Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback pathAug 12, 2026
- UnratedUnknown [CVE-2026-33264 +1] Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string ` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be importedAug 12, 2026