VendorsApacheapache-airflow-providers-googleany version
Vulnerabilities

Apache Software Foundation any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-25691
Apache Airflow Google Provider: Google Cloud Sql Provider Remote Command Execution
Published 2023-02-24 · Modified
9.8EPSS 0.016
CVE-2026-49297
Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)
Published 2026-07-06 · Analyzed
8.1EPSS 0.010
CVE-2026-45361
Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)
Published 2026-05-25 · Modified
8.1EPSS 0.008
CVE-2023-25692
Apache Airflow Google Provider: Google Cloud Sql Provider Denial Of Service
Published 2023-02-24 · Modified
7.5EPSS 0.018
CVE-2026-68868
Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables
Published 2026-08-12 · Analyzed
6.5EPSS 0.006