References https://cloud.tencent.com/developer/article/2134972 https://nvd.nist.gov/vuln/detail/cve-2022-24288 https://seclists.org/oss-sec/2022/q1/160 https://cloud.tencent.com/developer/article/2134972 https://www.dptech.com/index.php?m=content&c=index&a=file_down&fileurl=/uploadfile/2022/0308/20220308055606493.pdf https://www.sentinelone.com/vulnerability-database/cve-2022-24288/ https://github.com/advisories/GHSA-v3c9-j6h9-66v4 https://zhuanlan.zhihu.com/p/569819137 https://cloud.tencent.com/developer/information/os%E5%91%BD%E4%BB%A4%E6%B3%A8%E5%85%A5 https://access.redhat.com/security/cve/CVE-2022-24288 https://vulners.com/nuclei/NUCLEI:CVE-2022-24288 https://advisories.gitlab.com/pypi/apache-airflow/CVE-2022-24288/ https://blog.csdn.net/weixin_43080961/category_11819416.html https://www.sonicwall.com/blog/apache-airflow-dag-injection-vulnerability https://www.miggo.io/vulnerability-database/cve/CVE-2022-24288 https://www.vicarius.io/vsociety/posts/rce-via-example-dag-in-apache-airflow-cve-2022-40127
Related VulnerabilitiesPoCapache-livy-logs: Apache Livy - Logs ExposedApache Log4j2 远程代码执行漏洞(CVE-2021-44228)PoCCVE-2026-41042: Apache Gravitino < 1.2.1 - Unauthenticated Remote Code ExecutionPoCmaven-settings-xml-exposure: Apache Maven settings.xml Credentials - ExposureApache IoTDB 认证绕过与远程代码执行漏洞PoCCVE-2025-68493: Apache Struts XWork - XML External Entity InjectionPoCCVE-2024-42323: Apache HertzBeat < 1.6.0 - SnakeYAML Deserialization Remote Code ExecutionPoCCVE-2025-54988: Apache Tika - XXE InjectionPoCCVE-2026-44825: Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default CredentialsPoCCVE-2026-50229: Apache Tomcat - Cross-Site ScriptingApache Kafka UI /smartfilters/testexecutions 代码执行漏洞(CVE-2026-5562)Apache Druid /proxy/coordinator@ 服务器端请求伪造漏洞(CVE-2025-27888)