
CVE-2026-25604: Apache Airflow AWS Auth Manager: Host Header Injection Leading to SAML Authentication Bypass https://www.openwall.com/lists/oss-security/2026/03/09/6 the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL
Post summary
The text announces CVE-2026-25604, describing a Host Header Injection in Apache Airflow’s AWS Auth Manager that allows SAML authentication bypass, with no PoC, exploit tool, or mitigation mentioned.


