https://seclists.org/oss-sec/2026/q2/686: CVE-2026-45361: Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)
Published May 24, 2026
·Updated
Affected Software
1 affected component
pypi/apache-airflow-providers-google<22.0.0
Frequently Asked Questions
1
Who is exposed to this issue?
Airflow deployments using apache-airflow-providers-google versions before 22.0.0 are affected when they use ComputeEngineSSHHook to connect an Airflow worker to a Compute Engine VM. The relevant threat is an in-path network attacker able to intercept or modify that SSH session.
2
Is the unsafe behavior enabled by default?
Yes. ComputeEngineSSHHook uses Paramiko AutoAddPolicy by default, which disables SSH host-key verification.
3
What remediation is available?
Upgrade apache-airflow-providers-google to version 22.0.0 or later.