In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager.
History

Tue, 10 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache airflow Providers Amazon
CPEs cpe:2.3:a:apache:airflow_providers_amazon:*:*:*:*:*:*:*:*
Vendors & Products Apache airflow Providers Amazon

Tue, 10 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache-airflow-providers-amazon
Vendors & Products Apache
Apache apache-airflow-providers-amazon

Mon, 09 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 09 Mar 2026 11:00:00 +0000

Type Values Removed Values Added
Description In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager.
Title Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass
Weaknesses CWE-346
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-03-09T16:48:12.786Z

Reserved: 2026-02-03T09:59:31.342Z

Link: CVE-2026-25604

cve-icon Vulnrichment

Updated: 2026-03-09T12:09:58.818Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-09T11:16:06.077

Modified: 2026-03-10T18:58:48.887

Link: CVE-2026-25604

cve-icon Redhat

No data.