In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.
This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances.
You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager.
References
| Link | Resource |
|---|---|
| https://github.com/apache/airflow/pull/61368 | Issue Tracking Patch |
| https://lists.apache.org/thread/spwwrsmwxod7fpttcd7n7zs46j839l77 | Mailing List |
| http://www.openwall.com/lists/oss-security/2026/03/09/6 | Mailing List Third Party Advisory |
Configurations
History
10 Mar 2026, 18:58
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apache airflow Providers Amazon
Apache |
|
| References | () https://github.com/apache/airflow/pull/61368 - Issue Tracking, Patch | |
| References | () https://lists.apache.org/thread/spwwrsmwxod7fpttcd7n7zs46j839l77 - Mailing List | |
| References | () http://www.openwall.com/lists/oss-security/2026/03/09/6 - Mailing List, Third Party Advisory | |
| CPE | cpe:2.3:a:apache:airflow_providers_amazon:*:*:*:*:*:*:*:* | |
| Summary |
|
09 Mar 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
09 Mar 2026, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
09 Mar 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-09 11:16
Updated : 2026-03-10 18:58
NVD link : CVE-2026-25604
Mitre link : CVE-2026-25604
CVE.ORG link : CVE-2026-25604
JSON object : View
Products Affected
apache
- airflow_providers_amazon
CWE
CWE-346
Origin Validation Error
