CVE-2026-25604: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-25604 is a Host Header Injection vulnerability in the AWS Auth Manager component of Apache Airflow Providers Amazon that enables SAML authentication bypass. The flaw affects apache-airflow-providers-amazon versions 8.0.0 through 9.21.x, and was disclosed on March 9, 2026 by Apache via the oss-security mailing list. The vulnerability was discovered by Sungwuk Jung and carries a CVSS v3.1 base score of 5.4 (Medium) (Openwall oss-sec, Feedly).

Technical details

The root cause is an Origin Validation Error (CWE-346): the AWS Auth Manager component uses the host value as supplied by the client HTTP request rather than deriving it from the server's configured instance URL, allowing an attacker to manipulate the SAML authentication origin. By injecting a crafted Host header, a low-privileged attacker with network access can replay a valid SAML response obtained from one Airflow instance against a different instance, bypassing that instance's access controls. The fix, merged in PR #61368, replaces the client-supplied host with the value from the server configuration (GitHub PR, Openwall oss-sec).

Impact

Successful exploitation allows an attacker with low privileges to replay SAML authentication responses across different Apache Airflow instances, potentially gaining unauthorized access to instances with distinct and more permissive access control configurations. This results in unauthorized data access (low confidentiality impact) and the ability to perform unauthorized actions such as modifying DAGs or configurations (low integrity impact), with no direct availability impact. The cross-instance nature of the attack enables lateral movement across Airflow deployments sharing the same identity provider (Feedly, Openwall oss-sec).

Exploitability

As of the time of disclosure, there was no confirmed evidence of active in-the-wild exploitation, though a public proof-of-concept repository (CVE-2026-25604-PoC by John-Jung) appeared on GitHub and was indexed by Sploitus in late April 2026 (Feedly). The EPSS score is 0.01% (0.0001), indicating a currently low probability of exploitation. Exploitation requires low privileges (an authenticated account on at least one Airflow instance using AWS Auth Manager with SAML). The vulnerability is not listed in the CISA KEV catalog.

Exploitation steps

  1. Reconnaissance: Identify Apache Airflow instances using AWS Auth Manager with SAML authentication enabled, running apache-airflow-providers-amazon versions 8.0.0–9.21.x.
  2. Obtain a valid SAML response: Authenticate to a target Airflow instance (Instance A) where the attacker has legitimate low-privilege credentials, capturing the SAML response issued by the identity provider.
  3. Craft a malicious request: Prepare an authentication request to a second Airflow instance (Instance B) with a manipulated Host header set to the hostname of Instance A, so the SAML origin validation uses the attacker-controlled value.
  4. Replay the SAML response: Submit the SAML response from Instance A to Instance B's SAML assertion consumer endpoint with the spoofed Host header, bypassing origin verification.
  5. Gain unauthorized access: If successful, the attacker is authenticated to Instance B under the identity from Instance A, potentially with different (higher) access privileges depending on Instance B's access control configuration (GitHub PR, Openwall oss-sec).

Indicators of compromise

  • Network: HTTP requests to the Airflow SAML assertion consumer endpoint (e.g., /auth/saml/acs) containing a Host header value that does not match the server's configured instance URL; SAML POST requests originating from unexpected source IPs.
  • Logs: Airflow web server access logs showing SAML ACS endpoint requests with mismatched Host headers; authentication events for a user account on Instance B that has no prior login history on that instance.
  • Application: Successful logins to an Airflow instance by users who are not expected to have access to that specific instance; session creation events in Airflow logs immediately following a SAML assertion submission with an anomalous issuer or destination URL.

Mitigation and workarounds

Upgrade apache-airflow-providers-amazon to version 9.22.0 or later, which fixes the vulnerability by reading the host from the server configuration rather than the client-supplied request header (GitHub PR, Openwall oss-sec). No configuration-based workaround is documented; patching is the only recommended remediation. Organizations using AWS Auth Manager with SAML should prioritize this upgrade, particularly in multi-instance deployments where cross-instance lateral movement is a concern.

Community reactions

The vulnerability was publicly announced by Apache PMC member Jarek Potiuk on the oss-security mailing list on March 9, 2026, crediting Sungwuk Jung as the finder (Openwall oss-sec). A technical write-up describing the issue as a "Host Header Injection Leading to SAML Authentication Bypass" was published by Infinitsec shortly after disclosure. Rewterz included it in a threat advisory covering multiple Apache Airflow vulnerabilities (Rewterz Advisory). Social media activity on Bluesky noted the CVE publication, and the vulnerability was indexed by standard security tracking platforms including VulDB and CIRCL.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management