CVE-2026-45361General(apache / apache-airflow-providers-google)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to `apache-airflow-providers-google` 22.0.0 or later.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-322

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apache-airflow-providers-google

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-05-24); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
apache-airflow-providers-google

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-24: 1Mentions · 2026-05-25: 1Mentions · 2026-05-26: 1Mentions · 2026-05-27: 1Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 105-2405-2505-2605-27
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-241
General1
2026-05-251
Disclosure1
2026-05-261
General1
2026-05-271
General1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    General

    Apache Airflow CVE-2026-45361: Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default) https://www.openwall.com/lists/oss-security/2026/05/24/9 CVE-2026-46745: FAB provider: LDAP Filter Injection in FAB Auth Manager _search_ldap https://www.openwall.com/lists/oss-security/2026/05/24/10

    Post summary

    The excerpt lists two Apache Airflow CVEs with brief technical descriptions but lacks exploit code, patch information, or evidence of active exploitation.

    01050592
    4.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-45361 Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute E… https://www.cve.org/CVERecord?id=CVE-2026-45361

    Post summary

    The tweet discloses CVE‑2026‑45361, noting that the Apache Airflow providers‑google ComputeEngineSSHHook disables SSH host‑key verification by default, thereby exposing SSH traffic, but does not provide PoC, exploit, patch, or active exploitation details.

    00010240
    57.5K followersView on X
  • DailyCVE@dailycve
    General

    🔴 Apache Airflow providers-#google, SSH Host-Key Verification Disabled, #CVE-2026-45361 (Critical) https://dailycve.com/apache-airflow-providers-google-ssh-host-key-verification-disabled-cve-2026-45361-critical/

    Post summary

    The text announces CVE‑2026‑45361 in Apache Airflow providers with a brief reference link, but it lacks technical details, PoC, exploit code, or mitigation information.

    0000049
    207 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-45361 CVE-2026-45361 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45361

    Post summary

    The text merely references CVE‑2026‑45361 and includes a link to a vulnerability details page, with no additional context on exploits, patches, or technical specifics.

    0000066
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheapache-airflow-providers-google---

Explore more