Home

Description

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to `apache-airflow-providers-google` 22.0.0 or later.

PUBLISHED Reserved 2026-05-11 | Published 2026-05-25 | Updated 2026-05-25 | Assigner apache

Problem types

CWE-322: (Key Exchange without Entity Authentication)

Product status

Default status
unaffected

Any version before 22.0.0
affected

Credits

Jarek Potiuk remediation developer

References

github.com/apache/airflow/pull/66746 patch

lists.apache.org/thread/3lpj7ppwxp7jtp81rnxk75xvln7qd7h2 vendor-advisory

cve.org (CVE-2026-45361)

nvd.nist.gov (CVE-2026-45361)

Download JSON