CVE-2026-49486Patch(apache / apache-airflow-providers-ftp)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache apache-airflow-providers-ftp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTPSFileTransmitOperator` to move files over FTPS exposed file contents and credentials-in-transit to a network attacker able to observe the data connection. Upgrade apache-airflow-providers-ftp to `3.15.1` or later, which issues `PROT P` to encrypt the data channel.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-319

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apache-airflow-providers-ftp

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-27); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
apache-airflow-providers-ftp

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-27: 1Mentions · 2026-06-28: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-28: 106-2706-28
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-06-271
Patch1
2026-06-281
Disclosure1
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-49486: Apache Airflow FTP provider: Does not protect FTPS data channel (missing PROT_P) https://www.openwall.com/lists/oss-security/2026/06/26/1 although the control channel was TLS-protected the data channel was transmitted in cleartext

    Post summary

    Apache Airflow’s FTP provider fails to enforce FTPS data channel protection (missing PROT_P), resulting in cleartext transmission of data while the control channel is encrypted.

    00040494
    4.7K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH severity CVE-2026-49486 (CVSS 7.5) Apache Airflow FTP provider exposes FTPS data channel in cleartext, leaking file contents & credentials. Affected: FTPSHook/FTPSFileTransmitOperator Fix: Upgrade to v3.15.1+ #CVE #Vulnerability #PatchNow https://t.co/gTqw5VSNqa

    Post summary

    Apache Airflow's FTP provider has a clear‑text FTPS data channel leakage (CVE‑2026‑49486). Users are urged to upgrade to version 3.15.1+ to mitigate the vulnerability.

    0000040
    52 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheapache-airflow-providers-ftp---

Explore more