CVE-2026-25604

In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:airflow_providers_amazon:*:*:*:*:*:*:*:*

History

10 Mar 2026, 18:58

Type Values Removed Values Added
First Time Apache airflow Providers Amazon
Apache
References () https://github.com/apache/airflow/pull/61368 - () https://github.com/apache/airflow/pull/61368 - Issue Tracking, Patch
References () https://lists.apache.org/thread/spwwrsmwxod7fpttcd7n7zs46j839l77 - () https://lists.apache.org/thread/spwwrsmwxod7fpttcd7n7zs46j839l77 - Mailing List
References () http://www.openwall.com/lists/oss-security/2026/03/09/6 - () http://www.openwall.com/lists/oss-security/2026/03/09/6 - Mailing List, Third Party Advisory
CPE cpe:2.3:a:apache:airflow_providers_amazon:*:*:*:*:*:*:*:*
Summary
  • (es) En el gestor de AWS Auth, el origen de la autenticación SAML se ha utilizado tal como lo proporcionó el cliente y no se ha verificado contra la URL real de la instancia. Esto permitió obtener acceso a diferentes instancias con controles de acceso potencialmente diferentes al reutilizar la respuesta SAML de otras instancias. Debería actualizarse a la versión 9.22.0 del proveedor si utiliza el gestor de AWS Auth.

09 Mar 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

09 Mar 2026, 13:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/03/09/6 -

09 Mar 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 11:16

Updated : 2026-03-10 18:58


NVD link : CVE-2026-25604

Mitre link : CVE-2026-25604

CVE.ORG link : CVE-2026-25604


JSON object : View

Products Affected

apache

  • airflow_providers_amazon
CWE
CWE-346

Origin Validation Error