cbcvebase.
CVE-2026-45361
published 2026-05-25

CVE-2026-45361: Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a…

PriorityP349high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.59%
44.2th percentile
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to `apache-airflow-providers-google` 22.0.0 or later.

Affected

3 ranges
VendorProductVersion rangeFixed in
apacheapache-airflow-providers-google< 22.0.022.0.0
apacheapache-airflow-providers-google>= 0 < 22.0.022.0.0
apache_software_foundationapache_airflow_google_provider< 22.0.022.0.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.