CVE-2026-45361

ADVISORY - nist

Summary

Apache Airflow providers-google's ComputeEngineSSHHook disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to apache-airflow-providers-google 22.0.0 or later.

EPSS Score: 0.00071 (0.218)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Key Exchange without Entity Authentication


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in