Vulnerabilities (CVE)

Filtered by vendor Apache
Filtered by product Apache-airflow-providers-edge3
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-67895 1 Apache 1 Apache-airflow-providers-edge3 2025-12-22 N/A 9.8 CRITICAL
Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always development-only and not officially released, however if you installed and configured Edge3 provider in Airflow 2, it implicitly enabled non-public (normally) API which was used to test Edge Provider in Airflow 2 during the development. This API allowed Dag author to perform Remot ...

Show More