Cleartext Transmission of Sensitive Information Affecting apache-airflow-providers-ftp package, versions [,3.15.1rc1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWPROVIDERSFTP-17660780
  • published28 Jun 2026
  • disclosed26 Jun 2026
  • creditUnknown

Introduced: 26 Jun 2026

CVE-2026-49486  (opens in a new tab)
CWE-319  (opens in a new tab)

How to fix?

Upgrade apache-airflow-providers-ftp to version 3.15.1rc1 or higher.

Overview

apache-airflow-providers-ftp is a Provider package apache-airflow-providers-ftp for Apache Airflow

Affected versions of this package are vulnerable to Cleartext Transmission of Sensitive Information. due to the FTPSHook.get_conn process not invoking prot_p, resulting in the data channel being transmitted in cleartext. An attacker can intercept sensitive file contents and credentials by monitoring the network traffic between the client and server.

CVSS Base Scores

version 4.0
version 3.1