cbcvebase.

Apache Apache-Airflow-Providers-Google vulnerabilities

4 known vulnerabilities affecting apache/apache-airflow-providers-google.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3

Vulnerabilities

Page 1 of 1
CVE-2026-49297P3HIGHCVSS 8.1fixed in 22.2.12026-07-06
CVE-2026-49297 [HIGH] CWE-22 CVE-2026-49297: Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the source GCS bucket (typically a different trust principal than the DAG autho
nvd
CVE-2023-25691P3CRITICALCVSS 9.8fixed in 8.10.02023-02-24
CVE-2023-25691 [CRITICAL] CWE-20 CVE-2023-25691: Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects A Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.
ghsanvdosv
CVE-2026-45361P3HIGHCVSS 8.1fixed in 22.0.02026-05-25
CVE-2026-45361 [HIGH] CWE-322 CVE-2026-45361: Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by defau Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to `apache-airflow-providers-google` 22.0.0 or later.
ghsanvd
CVE-2023-25692P3HIGHCVSS 7.5fixed in 8.10.02023-02-24
CVE-2023-25692 [HIGH] CWE-20 CVE-2023-25692: Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects A Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.
ghsanvdosv
Apache Apache-Airflow-Providers-Google vulnerabilities | cvebase