API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were available.

Subscriptions

Vendors Products
Airflow Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-273c-4g26-4jpm Apache Airflow `/api/v2/dagReports` executes DAG Python in API
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 26 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

Thu, 30 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache airflow
Vendors & Products Apache
Apache airflow

Thu, 30 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
References

Thu, 30 Oct 2025 09:30:00 +0000

Type Values Removed Values Added
Description API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were available.
Title Apache Airflow: Airflow 3 API: /api/v2/dagReports executes DAG Python in API
Weaknesses CWE-250
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-02-26T16:56:52.558Z

Reserved: 2025-10-13T12:50:41.260Z

Link: CVE-2025-62402

cve-icon Vulnrichment

Updated: 2025-10-30T10:05:05.137Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-30T10:15:35.647

Modified: 2025-11-04T16:51:02.057

Link: CVE-2025-62402

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-30T14:37:19Z

Weaknesses