PT-2026-43023 · Apache Airflow · Apache Airflow Google Provider

·

CVE-2026-45361

·

Published

2026-05-25

·

Updated

2026-05-27

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions apache-airflow-providers-google versions prior to 22.0.0
Description The ComputeEngineSSHHook disables SSH host-key verification by default. This configuration exposes SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers, who may intercept or modify the session.
Recommendations Update to version 22.0.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45361
ECHO-C5A7-8DD9-27D6
GHSA-G9V5-GJWF-9RWX
PYSEC-2026-166

Affected Products

Apache Airflow Google Provider