CVE-2026-25604

MEDIUM

apache-airflow-providers-amazon < 9.22.0 - Origin Validation Error in AWS Auth Manager

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-25604. PoCs published by adminlove520, John-Jung.

AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2026-25604, demonstrating a Host Header Injection vulnerability in Apache Airflow's AWS Auth Manager that allows SAML authentication bypass. The PoC includes a mock vulnerable server and detailed reproduction steps.

Description

In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access controls by reusing SAML response from other instances. You should upgrade to 9.22.0 version of provider if you use AWS Auth Manager.

Exploits (2)

github WORKING POC 4 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2026/CVE-2026-25604

This repository contains a functional proof-of-concept for CVE-2026-25604, demonstrating a Host Header Injection vulnerability in Apache Airflow's AWS Auth Manager that allows SAML authentication bypass. The PoC includes a mock vulnerable server and detailed reproduction steps.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Apache Airflow with apache-airflow-providers-amazon (8.0.0 – 9.21.x)
No auth needed
Prerequisites: Python 3.8+ · AWS IAM Identity Center with SAML 2.0 configured · Access to SAML metadata URL
devstral-2 · analyzed May 11, 2026 Full analysis →
nomisec WORKING POC
by John-Jung · poc
https://github.com/John-Jung/CVE-2026-25604-PoC

This repository contains a functional PoC demonstrating CVE-2026-25604, a Host Header Injection vulnerability in Apache Airflow's AWS Auth Manager that allows SAML authentication bypass via malicious Host header manipulation.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Apache Airflow (apache-airflow-providers-amazon 8.0.0–9.21.x)
No auth needed
Prerequisites: Python 3.8+ · AWS IAM Identity Center with SAML 2.0 configured · Access to SAML metadata URL
devstral-2 · analyzed Apr 22, 2026 Full analysis →

Scores

CVSS v3 5.4
EPSS 0.0002
EPSS Percentile 3.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-346
Status published
Products (2)
apache/airflow_providers_amazon 8.0.0 - 9.22.0
pypi/apache-airflow-providers-amazon 0 - 9.22.0PyPI
Published Mar 09, 2026
Tracked Since Mar 09, 2026