Description

A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likelihood of it making any damage is low. You should upgrade to version 6.0.0 of the provider to avoid even that risk.

INFO

Published Date :

2026-03-09T10:19:58.034Z

Last Modified :

2026-03-10T03:55:27.322Z

Source :

apache
AFFECTED PRODUCTS

The following products are affected by CVE-2025-69219 vulnerability.

Vendors Products
Apache
  • Airflow Providers Http
  • Apache-airflow-providers-http
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-69219.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact