apache-airflow-providers-google has 3 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 8.1 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 1 prev 1
Products
- apache-airflow-providers-google 3
Worst active — by depth score
CVE-2026-49297High· 8.1Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by…45CVE-2026-45361High· 8.1Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an A…45CVE-2023-25692High· 7.5Apache Airflow Google Provider Improper Input Validation vulnerability42
apache-airflow-providers-google vulnerabilities
CVEs affecting apache-airflow-providers-google, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-49297High· 8.1Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by…
Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containme…
CVE-2026-45361High· 8.1Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an A…
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the s…
CVE-2023-25692High· 7.5Apache Airflow Google Provider Improper Input Validation vulnerability
Apache Airflow Google Provider Improper Input Validation vulnerability