Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Airflow Providers Google
APPApache< 8.10.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2026-49297HIGH8.1PL ✓same product
Path Traversal w Apache Airflow Google Provider — zapis plików poza docelowym katalogiem
CVE-2026-45361HIGH8.1same product
Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposi...
CVE-2023-25692HIGH7.5same product
Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airf...
CVE-2026-68868MEDIUM6.5same product
The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team sco...
CVE-2025-24813CRITICAL9.8⚠ KEVPL ✓same vendor
Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych