Missing Authentication for Critical Function in Apache Airflow Providers Edge3 - CVE-2025-67895

 

Missing Authentication for Critical Function in Apache Airflow Providers Edge3 - CVE-2025-67895

Published: December 17, 2025


Vulnerability identifier: #VU120172
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-67895
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the affected system.

The vulnerability exists due to the application exposes Edge3 Worker RPC via API endpoints. A remote Dag author can use the exposed endpoints to execute arbitrary code on the system.

The vulnerability affects Edge3 provider installations on Airflow 2. 


Affected software

Apache Airflow Providers Edge3

How to mitigate CVE-2025-67895

Install updates from vendor's website.

Apache Airflow Providers Edge3 - update to 2.0.0

External References

Related Security Bulletins