Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 01 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 01 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 27 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache apache-airflow-providers-google
|
|
| CPEs | cpe:2.3:a:apache:apache-airflow-providers-google:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache apache-airflow-providers-google
|
Tue, 26 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 26 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 25 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow Google Provider |
|
| Vendors & Products |
Apache
Apache airflow Google Provider |
Mon, 25 May 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to `apache-airflow-providers-google` 22.0.0 or later. | |
| Title | Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default) | |
| Weaknesses | CWE-322 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-06-01T15:48:53.991Z
Reserved: 2026-05-11T23:58:59.829Z
Link: CVE-2026-45361
Updated: 2026-05-25T11:27:12.183Z
Status : Modified
Published: 2026-05-25T10:16:15.087
Modified: 2026-06-17T10:51:57.870
Link: CVE-2026-45361
No data.
OpenCVE Enrichment
Updated: 2026-05-26T17:30:10Z