CVE-2025-62503
published 2025-10-30CVE-2025-62503: User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
PriorityP424medium4.6CVSS 3.1
AVNACLPRLUIRSUCLILAN
EPSS
0.40%
31.8th percentile
User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | airflow | >= 3.0.0 < 3.1.1 | 3.1.1 |
| apache_software_foundation | apache_airflow | >= 3.0.0 < 3.1.1 | 3.1.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Airflow's create action can upsert existing Pools/Connections/Variables
osv·2025-10-30
CVE-2025-62503 [MEDIUM] Apache Airflow's create action can upsert existing Pools/Connections/Variables
Apache Airflow's create action can upsert existing Pools/Connections/Variables
User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
GHSA
Apache Airflow's create action can upsert existing Pools/Connections/Variables
ghsa·2025-10-30
CVE-2025-62503 [MEDIUM] CWE-250 Apache Airflow's create action can upsert existing Pools/Connections/Variables
Apache Airflow's create action can upsert existing Pools/Connections/Variables
User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-30
Published