
Apache Airflow CVE-2026-45361: Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default) https://www.openwall.com/lists/oss-security/2026/05/24/9 CVE-2026-46745: FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap https://www.openwall.com/lists/oss-security/2026/05/24/10
Post summary
The excerpt lists two Apache Airflow CVEs with brief technical descriptions but lacks exploit code, patch information, or evidence of active exploitation.



