Key Exchange without Entity Authentication Affecting apache-airflow-providers-google package, versions [,22.0.0rc1)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.59% (44th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWPROVIDERSGOOGLE-16875085
  • published26 May 2026
  • disclosed25 May 2026
  • creditMythos

Introduced: 25 May 2026

CVE-2026-45361  (opens in a new tab)
CWE-322  (opens in a new tab)

How to fix?

Upgrade apache-airflow-providers-google to version 22.0.0rc1 or higher.

Overview

apache-airflow-providers-google is a Provider for Apache Airflow. Implements apache-airflow-providers-google package

Affected versions of this package are vulnerable to Key Exchange without Entity Authentication due to SSH host key verification being disabled by default in the ComputeEngineSSHHook process. An attacker can intercept or modify SSH sessions by performing a man-in-the-middle attack between the Airflow worker and the Compute Engine VM.

**Note: The fixed code still defaults to "auto_add", preserving the historical behavior of this hook; users are recommended to to review the settings accordingly.

CVSS Base Scores

version 4.0
version 3.1