Skip to content
Apache AirflowGHSA-gp5f-cx7h-8q6f

Apache Airflow's create action can upsert existing Pools/Connections/Variables

Medium4.6CVE-2025-62503 · Published Oct 30, 2025 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
>= 3.0.0, < 3.1.13.1.1
Details and references

User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-250
Also known as
BIT-airflow-2025-62503, CVE-2025-62503, PYSEC-2026-1133

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Oct 302025Apache Airflow `/api/v2/dagReports` executes DAG Python in API
CVE-2025-62402Medium5.4fixed in 3.1.1
Oct 302025Apache Airflow has a command injection vulnerability in "example_dag_decorator"
CVE-2025-54941Mediumfixed in 3.0.5
Sep 262025Apache Airflow: Connection sensitive details exposed to users with READ permissions
CVE-2025-54831Mediumfixed in 3.0.4
Dec 152025Apache Airflow exposes secret values to authenticated UI users via rendered templates
CVE-2025-66388Medium6.5fixed in 3.1.5
Dec 172025Edge3 Worker RPC RCE on Airflow 2.
CVE-2025-67895Critical9.8fixed in 2.0.0
Jan 16Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
CVE-2025-68438High7.5fixed in 3.1.6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.