CVE-2026-25604
Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.ย This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager.
| CWE | CWE-346 |
| Vendor | apache software foundation |
| Product | apache airflow providers amazon |
| Published | Mar 9, 2026 |
| Last Updated | Mar 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache airflow providers amazon
Be the first to know when new medium vulnerabilities affecting apache software foundation apache airflow providers amazon are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache Airflow Providers Amazon
8.0.0 < 9.22.0
References
Credits
Sungwuk Jung