GPU VulnDB

Database/Control plane, storage & DevOps

Apache Airflow: pre-3.2 deployments lack the isolation guarantees operators assumed, per clarified security model

CVSS 7.5CVE-2025-66236Control plane, storage & DevOpscurated

Impact

Apache Airflow before 3.2.0 did not provide the role and workload isolation that many deployment managers assumed it did; the project has now documented the actual security model, the workload isolation boundary and the JWT token authentication details explicitly, and shipped isolation improvements in 3.2.0. The record scores this as a confidentiality issue reachable over the network without authentication (C:H/I:N/A:N) but does not describe a single concrete code flaw, so treat it as a deployment-posture advisory rather than an exploit. It matters on a GPU fleet because Airflow is commonly the thing that submits training and batch inference jobs: a DAG author who is not supposed to be a cluster admin may in practice reach credentials or task context belonging to other teams' pipelines, and those credentials are the ones that hold GPU queues, object storage and model registries. Nothing here is specific to a GPU node - the exposure is in the orchestrator.

Who can reach it

Anyone who can author or modify a DAG, plus anyone who can reach the Airflow API or task execution interface with a token issued by the deployment. Whether authentication is required depends on how the deployment is configured, which is precisely the point of the advisory; the CVSS vector in the record assumes an unauthenticated network attacker.

What to do

Upgrade to Airflow 3.2.0 and then read and apply the now-explicit security model, workload isolation and JWT token authentication documents - the upgrade alone is not the whole fix, because the deployment manager is responsible for configuring the isolation. For most operators this is a scheduler, API server and worker restart on the control-plane hosts; GPU nodes running the resulting jobs do not need to be drained. Expect configuration review work alongside the version bump.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.