CVE-2026-49297Disclosure(apache / apache-airflow-providers-google)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the source GCS bucket (typically a different trust principal than the DAG author — partner uploads, ingest-only service accounts, public-data buckets) could create an object whose name contains `..` segments and cause the DAG run to write the downloaded blob outside the configured destination (the SFTP `destination_path` for `GCSToSFTPOperator`; the worker-local temp directory for `GCSTimeSpanFileTransformOperator`), enabling overwrite of arbitrary files on the SFTP server or the worker host. Affects deployments that ingest from buckets writable by less-trusted principals. Users are advised to upgrade to `apache-airflow-providers-google` 22.2.1 or later.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apache-airflow-providers-google

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-07-05); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
apache-airflow-providers-google

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-05: 1Mentions · 2026-07-07: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-07: 107-0507-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • vulntoday@vulntoday
    Disclosure

    🟠 HIGH CVE-2026-49297 Path traversal in Apache Airflow's Google provider (apache-airflow-providers-google before 22.2.1) lets a party with write access to a source GCS bucket overwrite arbitrary files on an SFTP server or Air… https://vuln.today/cve/CVE-2026-49297 #CVE #infosec

    Post summary

    The post announces a newly disclosed CVE-2026-49297 involving path traversal in Apache Airflow’s Google provider that permits arbitrary file overwrite on an SFTP server, but does not provide PoC, exploit code, or mitigation information.

    1900180698
    23 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-49297: Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator) https://www.openwall.com/lists/oss-security/2026/07/04/8 Severity: moderate

    Post summary

    CVE-2026-49297 is a moderate severity path traversal vulnerability in the Apache Airflow Google provider that allows traversal from GCS object names to local/SFTP filesystem. The notice provides technical details but does not include a PoC, exploit, patch, or evidence of active exploitation.

    011733.6K
    4.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheapache-airflow-providers-google---

Explore more