CVE-2025-69219Disclosure(apache / airflow_providers_http)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likelihood of it making any damage is low. You should upgrade to version 6.0.0 of the provider to avoid even that risk.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-913

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • airflow_providers_http

Threat summary

  • Public PoC is present in monitored signal
  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-03-09); latest day: 3
  • 8 total mentions across 2 days

Affected systems

Vendors
Products
airflow_providers_http

Deep dive

Activity timeline8 mentions / 2d
01345Mentions · 2026-03-09: 5Mentions · 2026-03-11: 3PoC Mentioned / Linked · 2026-03-11: 3Technical Details · 2026-03-09: 403-0903-11
Signal classification3 categories
Disclosure
450.0%
PoC
337.5%
General
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-095
Disclosure4General1
2026-03-113
PoC3
Full discourse8 posts
  • Clandestine@akaclandestine
    PoC

    GitHub - sak110/CVE-2025-69219 · GitHub https://github.com/sak110/CVE-2025-69219

    Post summary

    A GitHub repository link is provided for CVE-2025-69219, suggesting a PoC may be available, yet the text lacks details on exploits, patches, or active attacks.

    0401781.6K
    56.1K followersView on X
  • Clandestine@akaclandestine
    PoC

    CVE-2025-69219/poc.py at main · sak110/CVE-2025-69219 · GitHub https://github.com/sak110/CVE-2025-69219/blob/main/poc.py

    Post summary

    The post points to a GitHub repository containing a proof‑of‑concept file for CVE-2025-69219, with no further exploitation details, patch notes or technical context provided.

    020931.3K
    56.1K followersView on X
  • blueblue@piedpiper1616
    PoC

    GitHub - sak110/CVE-2025-69219 · GitHub - https://github.com/sak110/CVE-2025-69219

    Post summary

    A GitHub repository for CVE‑2025‑69219 is listed, indicating that PoC code is likely available, but no further technical or exploit details are provided.

    03026668
    5.5K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2025-69219: Apache Airflow Providers Http: Unsafe Pickle Deserialization in apache-airflow-providers-http leading to RCE via HttpOperator https://www.openwall.com/lists/oss-security/2026/03/09/1

    Post summary

    CVE-2025-69219 is an announced vulnerability in Apache Airflow Providers Http that permits remote code execution via unsafe pickle deserialization used by HttpOperator.

    00062554
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-69219 A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permiss… https://www.cve.org/CVERecord?id=CVE-2025-69219

    Post summary

    The text describes CVE-2025-69219 as enabling a database user to craft an entry that triggers code execution on Triggerer, but does not provide PoC, exploit, patch, or evidence of attacks.

    00000111
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-69219 - High A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since... https://www.thehackerwire.com/vulnerability/CVE-2025-69219/ https://t.co/NVw4OPd35J

    Post summary

    The tweet announces CVE‑2025‑69219 as a high‑severity flaw, detailing how an attacker with database access could manipulate entries to execute code and elevate privileges to Dag Author.

    0000094
    129 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-69219 - Apache Airflow Providers Http: Unsafe Pickle Deserialization in apache-airflow-providers-http leading to RCE via HttpOperator Intel Report: https://ift.tt/n9WyUwV

    Post summary

    The alert announces CVE‑2025‑69219, noting unsafe pickle deserialization in Apache Airflow Providers Http that could lead to RCE via HttpOperator, but does not provide evidence of active exploitation, patches, or PoC details.

    0000069
    347 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-69219 CVE-2025-69219 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69219 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post merely names CVE‑2025‑69219 and provides a link to a vulnerability details page, offering no further technical or actionable information.

    0000092
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheairflow_providers_http---

Explore more