7.5
CVSS V3
Status
Impact
The Starlette vulnerability (CVE-2025-62727) exists in a transitive dependency through FastAPI. Apache Airflow Core 3.1.1 has a hard constraint on fastapi[standard-no-fastapi-cloud-cli]>=0.116.0,<0.118.0, which prevents upgrading to FastAPI 0.118.0+ that supports Starlette 0.49.1 (the patched version). The fix requires upstream Apache Airflow to release a version with relaxed FastAPI constraints.
Status