VYPR

apk package

chainguard/airflow-2

pkg:apk/chainguard/airflow-2

Vulnerabilities (90)

  • CVE-2026-55558MedAug 20, 2026
    affected < 2.11.2-r18fixed 2.11.2-r18

    aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS handshake without clearing SMTPProtocol._buffer. An active network attacker can place attacke

  • CVE-2026-53533MedAug 18, 2026
    affected < 2.11.2-r18fixed 2.11.2-r18

    aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line break is framed as additional standalone SMTP comma

  • CVE-2026-71491HigAug 17, 2026
    affected < 2.11.2-r16fixed 2.11.2-r16

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption through sqlparse.parse() and sqlparse.format

  • CVE-2026-59894MedAug 17, 2026
    affected < 2.11.2-r16fixed 2.11.2-r16

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the corresponding sqlformat -l modes, allowing crafted SQ

  • CVE-2026-59893HigAug 17, 2026
    affected < 2.11.2-r16fixed 2.11.2-r16

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters, causing quadratic CPU consumption through

  • CVE-2026-54284HigAug 17, 2026
    affected < 2.11.2-r16fixed 2.11.2-r16

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing quadratic CPU consumption through sqlparse.

  • CVE-2026-45309HigJul 17, 2026
    affected < 2.11.2-r17fixed 2.11.2-r17

    AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.0, AsyncSSH expands the OpenSSH-compatible AuthorizedKeysFile %u token in asyncssh/config.py, asyncssh/connecti

  • CVE-2026-15925CriJul 16, 2026
    affected < 2.11.2-r19fixed 2.11.2-r19

    Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access cou

  • CVE-2026-15736HigJul 14, 2026
    affected < 2.11.2-r20fixed 2.11.2-r20

    Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through attacker-controlled input keys. An attacker may be able to exploit this t

  • CVE-2026-54591HigJul 8, 2026
    affected < 2.11.2-r17fixed 2.11.2-r17

    AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.1, a malicious SSH server can write arbitrary files on the asyncssh SCP client's filesystem by sending filename

  • CVE-2026-54590MedJul 8, 2026
    affected < 2.11.2-r17fixed 2.11.2-r17

    AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Version 2.23.0 contains an incomplete fix for CVE-2026-45309 in SSHServerConfig._set_tokens that blocks /, , and .. before %u

  • CVE-2026-49486HigJun 26, 2026
    affected < 2.11.2-r21fixed 2.11.2-r21

    The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTPSFileTransmitOperato

  • CVE-2026-49468CriJun 22, 2026
    affected < 2.11.2-r12fixed 2.11.2-r12

    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effecti

  • CVE-2026-44492HigJun 11, 2026
    affected < 2.11.2-r12fixed 2.11.2-r12

    Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:

  • CVE-2026-45360HigJun 1, 2026
    affected < 2.11.2-r19fixed 2.11.2-r19

    Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary class paths drawn from DAG-author-controlled serialized state without an allowlist or plugin-registry gate. A DAG author whose code rea

  • CVE-2026-41425MedApr 24, 2026
    affected < 2.11.2-r8fixed 2.11.2-r8

    Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.

  • CVE-2026-41205HigApr 23, 2026
    affected < 2.11.2-r9fixed 2.11.2-r9

    Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable

  • CVE-2026-40347MedApr 18, 2026
    affected < 2.11.2-r9fixed 2.11.2-r9

    Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the

  • CVE-2025-66236HigApr 13, 2026
    affected < 2.11.2-r11fixed 2.11.2-r11

    Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager could make were not clear or explicit enoug

  • CVE-2026-39892CriApr 8, 2026
    affected < 2.11.2-r8fixed 2.11.2-r8

    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulner

Page 1 of 5