High severity7.5NVD Advisory· Published Jun 26, 2026· Updated Sep 16, 2026
CVE-2026-49486
CVE-2026-49486
Description
The Apache Airflow FTP provider's FTPSHook.get_conn() created an ftplib.FTP_TLS connection but never called prot_p(), so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using FTPSHook or FTPSFileTransmitOperator to move files over FTPS exposed file contents and credentials-in-transit to a network attacker able to observe the data connection. Upgrade apache-airflow-providers-ftp to 3.15.1 or later, which issues PROT P to encrypt the data channel.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-airflow-providers-ftpPyPI | < 3.15.1 | 3.15.1 |
Affected products
4cpe:2.3:a:apache:apache-airflow-providers-ftp:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apache:apache-airflow-providers-ftp:*:*:*:*:*:*:*:*range: <3.15.1
- (no CPE)range: >=3.15.1
Patches
Vulnerability mechanics
References
8- github.com/apache/airflow/pull/67946nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-fgch-86x8-fv43ghsaADVISORY
- lists.apache.org/thread/gwnsxlt9hfj5pc543wxtogbnjdn04xj1nvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-49486ghsaADVISORY
- www.openwall.com/lists/oss-security/2026/06/26/1nvdWEB
- github.com/apache/airflow/commit/a929d142d667f71dea29c565a7167216a9c30378ghsaWEB
- github.com/apache/airflow/releases/tag/providers-ftp/3.15.1ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow-providers-ftp/PYSEC-2026-238.yamlghsaWEB
News mentions
0No linked articles in our index yet.