id: PYSEC-2026-1129 published: "2026-07-07T16:03:09.123674Z" modified: "2026-07-07T17:23:42.679540Z" aliases: - CVE-2025-62402 - GHSA-273c-4g26-4jpm summary: Apache Airflow `/api/v2/dagReports` executes DAG Python in API details: API users via `/api/v2/dagReports` could perform Dag code execution in the context of the api-server if the api-server was deployed in the environment where Dag files were available. affected: - package: name: apache-airflow ecosystem: PyPI purl: pkg:pypi/apache-airflow ranges: - type: ECOSYSTEM events: - introduced: 3.0.0 - fixed: 3.1.1 versions: - 3.0.0 - 3.0.1 - 3.0.1rc1 - 3.0.2 - 3.0.2rc1 - 3.0.2rc2 - 3.0.3 - 3.0.3rc1 - 3.0.3rc2 - 3.0.3rc3 - 3.0.3rc4 - 3.0.3rc5 - 3.0.3rc6 - 3.0.4 - 3.0.4rc1 - 3.0.4rc2 - 3.0.5 - 3.0.5rc1 - 3.0.5rc2 - 3.0.5rc3 - 3.0.6 - 3.0.6rc1 - 3.0.6rc2 - 3.1.0 - 3.1.0b1 - 3.1.0b2 - 3.1.0rc1 - 3.1.0rc2 - 3.1.1rc1 - 3.1.1rc2 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2025-62402 - type: WEB url: https://github.com/apache/airflow/pull/56609 - type: WEB url: https://github.com/apache/airflow/commit/828aaa0b1d95caf90612a648867c17aec7e87874 - type: PACKAGE url: https://github.com/apache/airflow - type: WEB url: https://lists.apache.org/thread/vbzxnxn031wb998hsd7vqnvh4z8nx6rs - type: WEB url: http://www.openwall.com/lists/oss-security/2025/10/29/7 - type: PACKAGE url: https://pypi.org/project/apache-airflow - type: ADVISORY url: https://github.com/advisories/GHSA-273c-4g26-4jpm severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N