{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-22T18:45:11.700","vulnerabilities":[{"cve":{"id":"CVE-2026-25604","sourceIdentifier":"security@apache.org","published":"2026-03-09T11:16:06.077","lastModified":"2026-03-10T18:58:48.887","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. \nThis allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances.\n\nYou should upgrade to 9.22.0 version of provider if you use AWS Auth Manager."},{"lang":"es","value":"En el gestor de AWS Auth, el origen de la autenticación SAML se ha utilizado tal como lo proporcionó el cliente y no se ha verificado contra la URL real de la instancia.\nEsto permitió obtener acceso a diferentes instancias con controles de acceso potencialmente diferentes al reutilizar la respuesta SAML de otras instancias.\n\nDebería actualizarse a la versión 9.22.0 del proveedor si utiliza el gestor de AWS Auth."}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-346"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:airflow_providers_amazon:*:*:*:*:*:*:*:*","versionStartIncluding":"8.0.0","versionEndExcluding":"9.22.0","matchCriteriaId":"9A3CFD46-11DF-4D34-B4AB-030546AD6920"}]}]}],"references":[{"url":"https://github.com/apache/airflow/pull/61368","source":"security@apache.org","tags":["Issue Tracking","Patch"]},{"url":"https://lists.apache.org/thread/spwwrsmwxod7fpttcd7n7zs46j839l77","source":"security@apache.org","tags":["Mailing List"]},{"url":"http://www.openwall.com/lists/oss-security/2026/03/09/6","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]}]}}]}