CVE-2025-62503: Apache Airflow
Medium severity, CVSS 4.6. EPSS: 0.4% chance of exploitation in the next 30 days.
User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
Affected products
- Apache Airflow: from 3.0.0, before 3.1.1 (fixed in 3.1.1)
Published 2025-10-30. Last modified 2026-10-08.