VYPR

Apache Airflow Providers Apache Pig

by Apache

Source repositories

CVEs (2)

  • CVE-2022-40189CriNov 22, 2022
    risk 0.57cvss 9.8epss 0.04

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue…

  • CVE-2026-58065HigJul 13, 2026
    risk 0.00cvss 8.1epss 0.00

    The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server…