Key Exchange without Entity Authentication Affecting apache-airflow-providers-git package, versions [,0.4.1)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.74% (52nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWPROVIDERSGIT-17963584
  • published14 Jul 2026
  • disclosed13 Jul 2026
  • creditSiyang Wu

Introduced: 13 Jul 2026

CVE-2026-58065  (opens in a new tab)
CWE-322  (opens in a new tab)

How to fix?

Upgrade apache-airflow-providers-git to version 0.4.1 or higher.

Overview

apache-airflow-providers-git is a Provider package apache-airflow-providers-git for Apache Airflow

Affected versions of this package are vulnerable to Key Exchange without Entity Authentication via the GitHook SSH transport options in airflow/providers/git/hooks/git.py. An attacker who can intercept traffic between an Airflow worker and the Git server can impersonate the server by supplying any SSH host key, then capture the deploy key or inject malicious repository content by triggering a Git clone over SSH with the default connection settings. This affects deployments that use the Git DAG bundle or Git provider over SSH, causing Airflow to fetch attacker-controlled code instead of the intended repository content.

CVSS Base Scores

version 4.0
version 3.1