CVE-2025-69219High· 8.8▾ MidnightPoC availableApache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.7%
2 GitHub repos
Last analysed / modified upstream
A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likelihood of it making any damage is low.
Users should upgrade to version 6.0.0 of the provider to avoid even that risk.
apache-airflow-providers-http < 6.0.0Upgrade to a patched release:
apache-airflow-providers-http 6.0.0Field changes observed since this record was first indexed.