VDB
KO
HIGH 8.1

PYSEC-2026-166

Details

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to `apache-airflow-providers-google` 22.0.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / apache-airflow-providers-google
Introduced in: 0 Fixed in: 22.0.0
Fix pip install --upgrade 'apache-airflow-providers-google>=22.0.0'

References