CVE-2025-27018
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider.
Does this matter?
Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider. When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0. Users are recommended to upgrade to version 6.2.0, which fixes the issue.
- CVSS 3.1
- 6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- apache/apache-airflow-providers-mysql
- Source
- security@apache.org
References
- https://github.com/apache/airflow/pull/47254Issue Tracking
- https://github.com/apache/airflow/pull/47255Issue Tracking
- https://lists.apache.org/thread/m8ohgkwz4mq9njohf66sjwqjdy28gvzfMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/03/19/4Mailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.