GHSA-9r5j-7r2x-rv4g · Severity: high · Ecosystem: pip — Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likelihood of it making any damage is low. You should upgrade to version 6.0.0 of the provider to avoid even that risk.
Conclusion & alert: CVE-2025-69219 is rated Low Risk (36.6/100): CVSS High severity, with low exploitation likelihood (EPSS 0.02%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-21 | 0.05% | 0.02% | -0.03% |
| 2 | 2026-03-11 | 0.01% | 0.05% | +0.04% |
| 3 | 2026-03-09 | — | 0.01% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-9r5j-7r2x-rv4g · Severity: high · Ecosystem: pip — Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | airflow_providers_http | >= 5.1.0, < 6.0.0 | cpe:2.3:a:apache:airflow_providers_http:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/apache/airflow/pull/61662 | Issue Tracking Patch |
| https://lists.apache.org/thread/zjkfb2njklro68tqzym092r4w65m5dq0 | Mailing List |
| http://www.openwall.com/lists/oss-security/2026/03/09/1 | Mailing List Third Party Advisory |