Junglewise Threat Intelligence

CVE-2026-25604: Apache Airflow AWS Auth Manager SAML authentication bypass

CVE-2026-25604 · Severity: medium · CVSS 5.4 · Published 2026-03-09

Technologies: apache-airflow-providers-amazon (PyPI). Vendors: Apache Software Foundation, PyPI.

Executive brief

A security flaw in the Apache Airflow AWS Auth Manager allows users to bypass authentication controls. By manipulating the web address provided during the login process, an attacker could reuse security credentials from one system to gain unauthorized access to another. This could lead to unauthorized data access or administrative control over different Airflow environments.

Technical details

The AWS Auth Manager in Apache Airflow Providers Amazon fails to verify the SAML authentication origin against the actual instance URL, instead relying on client-provided host headers. This 'Origin Validation Error' (CWE-346) allows an attacker to perform a host header injection, enabling the reuse of a valid SAML response from one instance to authenticate against a different instance. An attacker with low privileges can exploit this over the network without user interaction to bypass access controls. The issue is resolved in version 9.22.0 by ensuring the host is validated against the internal configuration rather than the request header.

Affected products

  • Apache Software Foundation Apache Airflow Providers Amazon 8.0.0 to < 9.22.0

Timeline

  • 2026-02-03: patched: Fix merged into Apache Airflow main branch
  • 2026-03-09: disclosed
  • 2026-03-09: advisory

References

Related threats