
CVE-2026-41016 Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgr… https://www.cve.org/CVERecord?id=CVE-2026-41016
Post summary
The CVE details a missing SSL context during TLS upgrade in Apache Airflow's SMTP hook, which could allow attackers to bypass certificate validation.

