GHSA-g9v5-gjwf-9rwxHighCVSS 8.1
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default
🔗 CVE IDs covered (1)
📋 Description
Apache Airflow providers-google's ComputeEngineSSHHook disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to apache-airflow-providers-google 22.0.0 or later.
🎯 Affected products1
- pip/apache-airflow-providers-google:>= 0, < 22.0.0
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-45361
- https://github.com/apache/airflow/pull/66746
- https://lists.apache.org/thread/3lpj7ppwxp7jtp81rnxk75xvln7qd7h2
- http://www.openwall.com/lists/oss-security/2026/05/24/9
- https://github.com/apache/airflow/commit/120dbed3462cedcb980aac022c587ba434249eb1
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow-providers-google/PYSEC-2026-166.yaml
- https://github.com/advisories/GHSA-g9v5-gjwf-9rwx