Apache AirflowGHSA-273c-4g26-4jpm
Apache Airflow `/api/v2/dagReports` executes DAG Python in API
Medium5.4CVE-2025-62402 · Published Oct 30, 2025 · updated Jul 7, 2026
API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were available.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | >= 3.0.0, < 3.1.1 | 3.1.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-250
- Also known as
- BIT-airflow-2025-62402, CVE-2025-62402, PYSEC-2026-1129
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 16 | Apache Airflow proxy credentials for various providers might leak in task logs | High7.5 | 2.11.1+1 more |
| Dec 172025 | Edge3 Worker RPC RCE on Airflow 2 | Critical9.8 | 2.0.0 |
| Dec 152025 | Apache Airflow exposes secret values to authenticated UI users via rendered templates | Medium6.5 | 3.1.5 |
| Oct 302025 | Apache Airflow's create action can upsert existing Pools/Connections/Variables | Medium4.6 | 3.1.1 |
| Oct 302025 | Apache Airflow has a command injection vulnerability in "example_dag_decorator" | Medium | 3.0.5 |
| Sep 262025 | Apache Airflow: Connection sensitive details exposed to users with READ permissions | Medium | 3.0.4 |