PT-2026-24022 · Apache · Apache Airflow Ftp Provider

·

CVE-2025-69219

·

Published

2026-03-08

·

Updated

2026-07-13

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Airflow Providers Http versions prior to 6.0.0
Description A user with database access can create a malicious database entry that executes code on the Triggerer, granting them the same permissions as a Dag Author. Direct database access is not typical for Airflow, reducing the likelihood of exploitation. The issue involves unsafe pickle deserialization in the HttpOperator.
Recommendations Upgrade to version 6.0.0 of the provider to address the issue.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03002
CVE-2025-69219
ECHO-7803-48C3-BFAB
GHSA-9R5J-7R2X-RV4G
PYSEC-2026-2367

Affected Products

Apache Airflow Ftp Provider