CVE-2025-69219
A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likelihood of it making any damage is low. You should upgrade to version 6.0.0 of the provider to avoid even that risk.
Published:Mar 9, 2026
Last Modified:Mar 10, 2026
EPS:Mar 9, 2026
EPSS Score:0.00033
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Apache
Product
Airflow Providers Http
Apache
Airflow Providers Http
Vendor
Apache
Product
Apache-airflow-providers-http
Apache
Apache-airflow-providers-http
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
