CVE-2026-33212: Celery Task Pending State Missing Authorization
Authorization is bypassed when a Celery AsyncResult task is in PENDING state or its result is an Exception. Setting the associated resource object to None in this branch causes all downstream permission checks to be skipped entirely (they exist only in the else branch), allowing any authenticated user to retrieve task data for restricted resources they canno
greprules fetch cve-2026-33212-celery-task-pending-state-missing-authorization --engine opengrepDescription
Authorization is bypassed when a Celery AsyncResult task is in PENDING state or its result is an Exception. Setting the associated resource object to None in this branch causes all downstream permission checks to be skipped entirely (they exist only in the else branch), allowing any authenticated user to retrieve task data for restricted resources they canno
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.