Missing Authentication for Critical Function in Apache Airflow Providers Edge3 - CVE-2025-67895
Published: December 17, 2025
Vulnerability identifier: #VU120172
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-67895
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to the application exposes Edge3 Worker RPC via API endpoints. A remote Dag author can use the exposed endpoints to execute arbitrary code on the system.
The vulnerability affects Edge3 provider installations on Airflow 2.
Affected software
Apache Airflow Providers Edge3
How to mitigate CVE-2025-67895
Install updates from vendor's website.
Apache Airflow Providers Edge3 - update to 2.0.0