/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-558p-9f2r-q35f

Published

Last updated

https://images.chainguard.dev/security/CGA-558p-9f2r-q35f
Package

airflow-core-3

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-62727
  • GHSA-7f5h-v6xp-fcq8

Severity

7.5

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-62727

Updates

Status

Pending upstream fix

Impact

starlette is a transitive dependency brought in via fastapi. fastapi is restricted to <0.118.0 due to breaking changes introduced in fastapi 0.118.0. fastapi restricts starlette to the vulnerable version until 0.120.0. fastapi maintainers are aware of the 0.118.0 breaking changes and are working on compatibility. Reference: https://github.com/apache/airflow/pull/56239

Status

Under investigation


Safe Source for Open Source™
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing