CVE-2026-25604 affects the Apache Airflow Amazon provider package (apache-airflow-providers-amazon), specifically the AWS Auth Manager component, in versions 8.0.0 through before 9.22.0. The vulnerability arises because the origin used during SAML authentication is accepted from client-supplied input and is not validated against the actual Airflow instance URL. As a result, a SAML response generated for one Airflow instance can be reused against a different instance. This is effectively an origin/host trust failure in the SAML authentication flow that can lead to authentication bypass across instances with different access controls.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused proof-of-concept for CVE-2026-25604, a Host header injection / origin validation flaw in Apache Airflow's AWS Auth Manager SAML flow. The repo contains only two files: a detailed README explaining the vulnerability, affected versions, attack scenarios, setup, and patch details; and a single Python script, mock_airflow.py, which implements a vulnerable Flask-based mock Airflow service. The exploit capability is authentication bypass via SAML response capture and replay. The PoC reproduces the vulnerable logic by reading the Host header directly from the incoming request in _prepare_request_VULNERABLE(), splitting it into hostname and port, and feeding those values into the SAML service provider configuration. In _init_saml_auth(), the script constructs assertionConsumerService.url as http://<host-from-header>:<port-from-header>/login_callback. Because this ACS URL is derived from attacker-controlled input, a request to /login with a spoofed Host header causes the generated AuthnRequest to direct the IdP to send the signed SAMLResponse to an attacker-controlled endpoint instead of the legitimate Airflow instance. Operational flow in the code: the /login route logs the Host header, initializes SAML auth, and redirects the client to the IdP login URL. The /login_callback route accepts POSTed SAMLResponse data, processes it with python3-saml, and if authentication succeeds, returns a success page and sets a session cookie. This makes the repository more than a pure documentation PoC: it is runnable exploit-demonstration code that shows both the vulnerable request preparation and the replay/processing path. Fingerprintable targets and endpoints include the local Flask routes /, /login, and /login_callback; the dynamically generated ACS URL; the example AWS IAM Identity Center metadata URL; and the example attacker-controlled hosts attacker.com:9090 and evil.com:8080 used in the documentation. The PoC binds on 0.0.0.0 and defaults to port 8080. Overall, the repository's purpose is educational and demonstrative: it does not automate phishing infrastructure or token interception itself, but it clearly shows how a vulnerable Airflow deployment can be coerced into generating a malicious ACS URL and how a captured SAMLResponse can then be replayed to obtain authenticated access.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.