CVE-2026-68868
- EPSS 0.57%
- Veröffentlicht 12.08.2026 10:27:56
- Zuletzt bearbeitet 17.08.2026 19:07:09
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary,...
CVE-2026-49297
- EPSS 0.7%
- Veröffentlicht 06.07.2026 09:54:07
- Zuletzt bearbeitet 08.07.2026 14:53:39
Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A u...
CVE-2026-45361
- EPSS 0.59%
- Veröffentlicht 25.05.2026 09:34:01
- Zuletzt bearbeitet 21.07.2026 19:10:00
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users...
CVE-2023-25691
- EPSS 1.58%
- Veröffentlicht 24.02.2023 12:15:30
- Zuletzt bearbeitet 11.03.2025 21:15:39
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.
CVE-2023-25692
- EPSS 1.83%
- Veröffentlicht 24.02.2023 12:15:30
- Zuletzt bearbeitet 11.03.2025 21:15:40
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.