Apache-airflow-providers-google
This hub aggregates every CVE we track for Apache-airflow-providers-google, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
1
Critical
3
High
0
In CISA KEV
Severity distribution
HIGH3MEDIUM1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
1
1
2024-092026-08
Latest CVEs
The 5 most recently published vulnerabilities affecting Apache-airflow-providers-google.
- CVE-2026-68868Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables6.5
- CVE-2026-49297Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)8.1
- CVE-2026-45361Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)8.1
- CVE-2023-25692Apache Airflow Google Provider: Google Cloud Sql Provider Denial Of Service7.5
- CVE-2023-25691Apache Airflow Google Provider: Google Cloud Sql Provider Remote Command Execution9.8
Product normalization is registry-driven with AI assist and human review. How it works