VYPR

Airflow Git provider

by Apache

CVEs (1)

  • CVE-2026-58065Jul 13, 2026
    risk 0.00cvss epss 0.00

    The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server…