CVE-2024-25141: Apache Apache-Airflow-Providers-Mongo

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.

Affected products

  • Apache Apache-Airflow-Providers-Mongo: from 1.0.0, before 4.0.0 (fixed in 4.0.0)

Published 2024-02-20. Last modified 2026-06-17.