Known Vulnerabilities for Apache-airflow-providers-ftp by Apache
Listed below are 1 of the newest known vulnerabilities associated with "Apache-airflow-providers-ftp" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-68872 json | The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scop... | Not Provided | 2026-08-10 | 2026-08-11 |
| CVE-2026-68871 json | The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id throu... | Not Provided | 2026-08-10 | 2026-08-12 |
| CVE-2026-68870 json | The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variabl... | Not Provided | 2026-08-10 | 2026-08-12 |
| CVE-2026-68868 json | The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolvi... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-59245 json | In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource ... | Not Provided | 2026-07-13 | 2026-07-14 |
| CVE-2026-59243 json | The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker abl... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-58065 json | The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH ho... | Not Provided | 2026-07-13 | 2026-07-14 |
| CVE-2026-50203 json | A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or comp... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-49818 json | The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a contai... | Not Provided | 2026-06-09 | 2026-06-10 |
| CVE-2026-49486 json | The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, s... | Not Provided | 2026-06-26 | 2026-06-26 |