PT-2026-93422 · Apache · Apache Airflow Apache Kafka Provider
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Airflow Apache Kafka provider versions 1.15.0 through 1.9.9
Description
The software resolves dotted-path strings found in a Kafka connection's
extra field into Python callables using the import string function without an allowlist. These callables are then passed to the confluent-kafka client for invocation. In deployments where the Kafka event producer is enabled via dag run events enabled or task instance events enabled, the client is built within the scheduler process. This allows a user with permissions to edit Airflow connections to achieve arbitrary code execution in the control plane, bypassing the security model that typically limits such users to code execution on workers. This issue affects plain brokers and Amazon MSK, while Google Managed Kafka is not affected as it overwrites the oauth cb variable.Recommendations
Upgrade to apache-airflow-providers-apache-kafka version 2.0.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow Apache Kafka Provider