PT-2026-52668 · Apache Airflow · Apache Airflow Ftp Provider

·

CVE-2026-49486

·

Published

2026-06-03

·

Updated

2026-06-28

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions apache-airflow-providers-ftp versions prior to 3.15.1
Description The FTPSHook.get conn() function in the Apache Airflow FTP provider creates an ftplib.FTP TLS connection without calling prot p(). This results in the data channel being transmitted in cleartext, even though the control channel is TLS-protected. Consequently, deployments utilizing FTPSHook or FTPSFileTransmitOperator to transfer files over FTPS expose file contents and credentials-in-transit to network attackers capable of observing the data connection.
Recommendations Update apache-airflow-providers-ftp to version 3.15.1 or later.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09198
CVE-2026-49486
GHSA-FGCH-86X8-FV43
PYSEC-2026-238

Affected Products

Apache Airflow Ftp Provider