CVE-2026-45361: Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default
(updated )
Apache Airflow providers-google’s ComputeEngineSSHHook disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to apache-airflow-providers-google 22.0.0 or later.
References
- github.com/advisories/GHSA-g9v5-gjwf-9rwx
- github.com/apache/airflow/commit/120dbed3462cedcb980aac022c587ba434249eb1
- github.com/apache/airflow/pull/66746
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow-providers-google/PYSEC-2026-166.yaml
- lists.apache.org/thread/3lpj7ppwxp7jtp81rnxk75xvln7qd7h2
- nvd.nist.gov/vuln/detail/CVE-2026-45361
Code Behaviors & Features
Detect and mitigate CVE-2026-45361 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →