CVE-2026-45361: Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)
Apache Airflow providers-google's ComputeEngineSSHHook disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to apache-airflow-providers-google 22.0.0 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
apache-airflow-providers-googleto a version that resolves this vulnerability.Fixed in 22.0.0Patch CVE-2026-45361
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45361?
CVE-2026-45361 has a high severity rating of 8.1 according to the CVSS 3.1 scoring system.
What vulnerabilities does CVE-2026-45361 expose?
CVE-2026-45361 exposes SSH traffic to potential interception or modification by disabling SSH host-key verification.
How do I fix CVE-2026-45361?
To fix CVE-2026-45361, users should upgrade to the latest version of `apache-airflow-providers-google` where the patch is available.
What is affected by CVE-2026-45361?
CVE-2026-45361 affects the ComputeEngineSSHHook component within the Apache Airflow Google provider.
Is CVE-2026-45361 a remote code execution risk?
CVE-2026-45361 does not directly lead to remote code execution but poses a risk of session hijacking due to unverified SSH connections.