Unrated severityNVD Advisory· Published Jun 26, 2026· Updated Jun 26, 2026
Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)
CVE-2026-49486
Description
The Apache Airflow FTP provider's FTPSHook.get_conn() created an ftplib.FTP_TLS connection but never called prot_p(), so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using FTPSHook or FTPSFileTransmitOperator to move files over FTPS exposed file contents and credentials-in-transit to a network attacker able to observe the data connection. Upgrade apache-airflow-providers-ftp to 3.15.1 or later, which issues PROT P to encrypt the data channel.
Patches
Vulnerability mechanics
References
2- github.com/apache/airflow/pull/67946mitrepatch
- lists.apache.org/thread/gwnsxlt9hfj5pc543wxtogbnjdn04xj1mitrevendor-advisory
News mentions
0No linked articles in our index yet.