U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-27018

Change History

New CVE Received from Apache Software Foundation 3/19/2025 5:15:14 AM

Action Type Old Value New Value
Added Description

								
							
							
						
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider.

When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended.
It could lead to data corruption, modification and others.
This issue affects Apache Airflow MySQL Provider: before 6.2.0.

Users are recommended to upgrade to version 6.2.0, which fixes the issue.
Added CWE

								
							
							
						
CWE-89
Added Reference

								
							
							
						
https://github.com/apache/airflow/pull/47254
Added Reference

								
							
							
						
https://github.com/apache/airflow/pull/47255
Added Reference

								
							
							
						
https://lists.apache.org/thread/m8ohgkwz4mq9njohf66sjwqjdy28gvzf