{"id":"CVE-2023-25692","aliases":["GHSA-h8p2-8g72-qpgh","PYSEC-2026-774"],"url":"https://o3.security/vulnerability/CVE-2023-25692","summary":"Apache Airflow Google Provider: Google Cloud Sql Provider Denial Of Service","details":"Improper Input Validation vulnerability in the Apache Airflow Google Provider.\n\nThis issue affects Apache Airflow Google Provider versions before 8.10.0.\n\n","published":"2023-02-24T11:48:00.202Z","modified":"2026-08-08T03:47:43.807647961Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"apache-airflow-providers-google","fixedVersion":"8.10.0"}],"fix":{"url":"https://github.com/apache/airflow/pull/29499","label":"apache/airflow#29499"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25692.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/ks4l78l5rwdpmvfn7y7yhs179nyxtlsh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25692"},{"type":"FIX","url":"https://github.com/apache/airflow/pull/29499"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:43.807647961Z"}}