CVE Vulnerabilities

CVE-2026-45361

Key Exchange without Entity Authentication

Published: May 25, 2026 | Modified: Jun 01, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Apache Airflow providers-googles ComputeEngineSSHHook disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to apache-airflow-providers-google 22.0.0 or later.

Weakness

The product performs a key exchange with an actor without verifying the identity of that actor.

Affected Software

NameVendorStart VersionEnd Version
Apache-airflow-providers-googleApache*22.0.0 (excluding)

Potential Mitigations

References