Medium severity4.6NVD Advisory· Published Oct 30, 2025· Updated Jun 17, 2026
CVE-2025-62503
CVE-2025-62503
Description
User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflowPyPI | >= 3.0.0, < 3.1.1 | 3.1.1 |
Affected products
4- osv-coords2 versions
>= 3.0.0, < 3.1.1+ 1 more
- (no CPE)range: >= 3.0.0, < 3.1.1
- (no CPE)range: >= 3.0.0, < 3.1.1
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2025/10/29/8nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-gp5f-cx7h-8q6fghsaADVISORY
- lists.apache.org/thread/3v58249qscyn1hg240gh8hqg9pb4okcrnvdMailing ListVendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2025-62503ghsaADVISORY
- lists.apache.org/thread/ov923dyccwbv01v9mhcv7t7ykzobycfoghsaWEB
News mentions
0No linked articles in our index yet.