CVE-2026-25604Disclosure(apache / apache-airflow-providers-amazon)

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apache-airflow-providers-amazon

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Disclosures: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
apache-airflow-providers-amazon

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-09: 3Technical Details · 2026-03-09: 303-09
Signal classification2 categories
Disclosure
266.7%
Disclosures
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-25604: Apache Airflow AWS Auth Manager: Host Header Injection Leading to SAML Authentication Bypass https://www.openwall.com/lists/oss-security/2026/03/09/6 the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL

    Post summary

    The text announces CVE-2026-25604, describing a Host Header Injection in Apache Airflow’s AWS Auth Manager that allows SAML authentication bypass, with no PoC, exploit tool, or mitigation mentioned.

    00042617
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25604 In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to … https://www.cve.org/CVERecord?id=CVE-2026-25604

    Post summary

    The text announces a vulnerability (CVE-2026-25604) in AWS Auth manager that allows origin verification issues in SAML authentication, enabling potential exploitation.

    0000096
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosures

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-25604 - Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass Intel Report: https://ift.tt/ykDaV8l

    Post summary

    A threat alert announces CVE‑2026‑25604, a Host Header Injection that can bypass SAML authentication in Apache Airflow AWS Auth Manager, with technical details but no PoC, exploit code, patch, or active exploitation information provided.

    0000033
    347 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheapache-airflow-providers-amazon---

Explore more