PT-2026-52668 · Apache · Apache Airflow Ftp Provider
Andrew Rukin
+1
·
Published
2026-06-26
·
Updated
2026-06-26
·
CVE-2026-49486
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
The Apache Airflow FTP provider's
FTPSHook.get conn() created an ftplib.FTP TLS connection but never called prot p(), so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using FTPSHook or FTPSFileTransmitOperator to move files over FTPS exposed file contents and credentials-in-transit to a network attacker able to observe the data connection. Upgrade apache-airflow-providers-ftp to 3.15.1 or later, which issues PROT P to encrypt the data channel.Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow Ftp Provider