CVE-2025-62402: Apache Airflow
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were available.
Affected products
- Apache Airflow: from 3.0.0, before 3.1.1 (fixed in 3.1.1)
Published 2025-10-30. Last modified 2026-10-08.