id: PYSEC-2026-1133 published: "2026-07-07T16:03:08.998940Z" modified: "2026-07-07T17:23:42.946922Z" aliases: - CVE-2025-62503 - GHSA-gp5f-cx7h-8q6f summary: Apache Airflow's create action can upsert existing Pools/Connections/Variables details: User with CREATE and no UPDATE privilege for Pools, Connections, Variables could update existing records via bulk create API with overwrite action. affected: - package: name: apache-airflow ecosystem: PyPI purl: pkg:pypi/apache-airflow ranges: - type: ECOSYSTEM events: - introduced: 3.0.0 - fixed: 3.1.1 versions: - 3.0.0 - 3.0.1 - 3.0.1rc1 - 3.0.2 - 3.0.2rc1 - 3.0.2rc2 - 3.0.3 - 3.0.3rc1 - 3.0.3rc2 - 3.0.3rc3 - 3.0.3rc4 - 3.0.3rc5 - 3.0.3rc6 - 3.0.4 - 3.0.4rc1 - 3.0.4rc2 - 3.0.5 - 3.0.5rc1 - 3.0.5rc2 - 3.0.5rc3 - 3.0.6 - 3.0.6rc1 - 3.0.6rc2 - 3.1.0 - 3.1.0b1 - 3.1.0b2 - 3.1.0rc1 - 3.1.0rc2 - 3.1.1rc1 - 3.1.1rc2 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2025-62503 - type: PACKAGE url: https://github.com/apache/airflow - type: WEB url: https://lists.apache.org/thread/ov923dyccwbv01v9mhcv7t7ykzobycfo - type: WEB url: http://www.openwall.com/lists/oss-security/2025/10/29/8 - type: PACKAGE url: https://pypi.org/project/apache-airflow - type: ADVISORY url: https://github.com/advisories/GHSA-gp5f-cx7h-8q6f severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N