Moderate severityNVD Advisory· Published Oct 30, 2025· Updated Oct 30, 2025
Apache Airflow: Privilege boundary bypass in bulk APIs (create action can upsert existing Pools/Connections/Variables)
CVE-2025-62503
Description
User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflowPyPI | >= 3.0.0, < 3.1.1 | 3.1.1 |
Affected products
3- osv-coords2 versions
>= 3.0.0, < 3.1.1+ 1 more
- (no CPE)range: >= 3.0.0, < 3.1.1
- (no CPE)range: >= 3.0.0, < 3.1.1
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.