Apache AirflowGHSA-gp5f-cx7h-8q6f
Apache Airflow's create action can upsert existing Pools/Connections/Variables
Medium4.6CVE-2025-62503 · Published Oct 30, 2025 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | >= 3.0.0, < 3.1.1 | 3.1.1 |
Details and references
User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-250
- Also known as
- BIT-airflow-2025-62503, CVE-2025-62503, PYSEC-2026-1133
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 302025 | Apache Airflow `/api/v2/dagReports` executes DAG Python in API CVE-2025-62402Medium5.4fixed in 3.1.1 | Medium5.4 | 3.1.1 |
| Oct 302025 | Apache Airflow has a command injection vulnerability in "example_dag_decorator" CVE-2025-54941Mediumfixed in 3.0.5 | Medium | 3.0.5 |
| Sep 262025 | Apache Airflow: Connection sensitive details exposed to users with READ permissions CVE-2025-54831Mediumfixed in 3.0.4 | Medium | 3.0.4 |
| Dec 152025 | Apache Airflow exposes secret values to authenticated UI users via rendered templates CVE-2025-66388Medium6.5fixed in 3.1.5 | Medium6.5 | 3.1.5 |
| Dec 172025 | Edge3 Worker RPC RCE on Airflow 2. CVE-2025-67895Critical9.8fixed in 2.0.0 | Critical9.8 | 2.0.0 |
| Jan 16 | Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated CVE-2025-68438High7.5fixed in 3.1.6 | High7.5 | 3.1.6 |