Known Vulnerabilities for Apache Airflow FTP Provider by Apache Software Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Apache Airflow FTP Provider" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-68872 json | The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scop... | Not Provided | 2026-08-10 | 2026-08-11 |
| CVE-2026-68871 json | The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id throu... | Not Provided | 2026-08-10 | 2026-08-12 |
| CVE-2026-68870 json | The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variabl... | Not Provided | 2026-08-10 | 2026-08-12 |
| CVE-2026-68868 json | The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolvi... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-58065 json | The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH ho... | Not Provided | 2026-07-13 | 2026-07-14 |
| CVE-2026-50203 json | A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or comp... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-49818 json | The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a contai... | Not Provided | 2026-06-09 | 2026-06-10 |
| CVE-2026-49487 json | In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwarg... | Not Provided | 2026-07-07 | 2026-07-07 |
| CVE-2026-49486 json | The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, s... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-49297 json | Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names... | Not Provided | 2026-07-06 | 2026-07-06 |