CVE & CISA-KEV Catalog

CVE-2025-67895

CRITICAL
9.8
CVSS v3
NVD

Description

Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always development-only and not officially released, however if you installed and configured Edge3 provider in Airflow 2, it implicitly enabled non-public (normally) API which was used to test Edge Provider in Airflow 2 during the development. This API allowed Dag author to perform Remote Code Execution in the webserver context, which Dag Author was not supposed to be able to do. If you installed and configured Edge3 provider for Airflow 2, you should uninstall it and migrate to Airflow 3. The new Edge3 provider versions (>=2.0.0) has minimum version of Airflow set to 3 and the RCE-prone Airflow 2 code is removed, so it should no longer be possible to use the Edge3 provider 2.0.0+ on Airflow 2. If you used Edge Provider in Airflow 3, you are not affected.

How to fix

Remediation Available
apache-airflow-providers-edge3NVD
Affected:< 2.0.0Fixed in:2.0.0CVE-2025-67895derived from NVD

TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploit Intelligence

0.84%probability of exploitation in 30 days
54thpercentile

Moderate risk: more likely to be exploited than 54% of all known CVEs.

References

Related Vulnerabilities

Other CWE-669 vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2026-31431Medium5.596%KEVFix
CVE-2002-0055Medium5.035%--
CVE-2020-1048High7.817%--
CVE-2021-22900High7.214%KEV-
CVE-2026-25253High8.88.0%-Fix
CVE-2020-6862Medium5.36.3%--
Embed a live status badge for CVE-2025-67895
CVE-2025-67895 severity badge

Markdown

[![CVE-2025-67895](https://tridentstack.com/cve/badge/CVE-2025-67895.svg)](https://tridentstack.com/cve/CVE-2025-67895)

HTML

<a href="https://tridentstack.com/cve/CVE-2025-67895"><img src="https://tridentstack.com/cve/badge/CVE-2025-67895.svg" alt="CVE-2025-67895"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

See how it worksStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-12-22.