Apache Apache-Airflow-Providers-Google vulnerabilities
5 known vulnerabilities affecting apache/apache-airflow-providers-google.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-49297P3HIGHCVSS 8.1fixed in 22.2.12026-07-06
CVE-2026-49297 [HIGH] CWE-22 CVE-2026-49297: Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator
Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the source GCS bucket (typically a different trust principal than the DAG autho
ghsanvd
CVE-2023-25691P3CRITICALCVSS 9.8fixed in 8.10.02023-02-24
CVE-2023-25691 [CRITICAL] CWE-20 CVE-2023-25691: Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects A
Improper Input Validation vulnerability in the Apache Airflow Google Provider.
This issue affects Apache Airflow Google Provider versions before 8.10.0.
ghsanvdosv
CVE-2026-45361P3HIGHCVSS 8.1fixed in 22.0.02026-05-25
CVE-2026-45361 [HIGH] CWE-322 CVE-2026-45361: Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by defau
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to `apache-airflow-providers-google` 22.0.0 or later.
ghsanvd
CVE-2023-25692P3HIGHCVSS 7.5fixed in 8.10.02023-02-24
CVE-2023-25692 [HIGH] CWE-20 CVE-2023-25692: Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects A
Improper Input Validation vulnerability in the Apache Airflow Google Provider.
This issue affects Apache Airflow Google Provider versions before 8.10.0.
ghsanvdosv
CVE-2026-68868P3MEDIUMCVSS 6.5fixed in 22.3.02026-08-12
CVE-2026-68868 [MEDIUM] CWE-1220 CVE-2026-68868: The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied th
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team
nvd