Cleartext Transmission of Sensitive Information Affecting apache-airflow package, versions [,3.3.0b1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOW-17660779
  • published28 Jun 2026
  • disclosed26 Jun 2026
  • creditUnknown

Introduced: 26 Jun 2026

CVE-2026-49486  (opens in a new tab)
CWE-319  (opens in a new tab)

How to fix?

Upgrade apache-airflow to version 3.3.0b1 or higher.

Overview

apache-airflow is a platform to programmatically author, schedule, and monitor workflows.

Affected versions of this package are vulnerable to Cleartext Transmission of Sensitive Information due to the FTPSHook.get_conn process not invoking prot_p, resulting in the data channel being transmitted in cleartext. An attacker can intercept sensitive file contents and credentials by monitoring the network traffic between the client and server.

CVSS Base Scores

version 4.0
version 3.1