apache-airflow-providers-ftp vulnerabilities
CVEs whose affected-version data names the apache-airflow-providers-ftp package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-49486High· 7.5The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext
The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment u…
▾ Twilightapache · apache-airflow-providers-ftpEPSS 0.44%via NVD
CVE-2024-29733Low· 2.7Improper Certificate Validation vulnerability in Apache Airflow FTP Provider
Improper Certificate Validation vulnerability in Apache Airflow FTP Provider
▾ Sunlitapache-airflow-providers-ftp · apache-airflow-providers-ftpEPSS 0.63%via OSV