VYPR

apache-airflow-providers-apache-kafka

by Apache

CVEs (1)

  • CVE-2026-86792Sep 16, 2026
    risk 0.00cvss epss

    Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka client which invokes them. Deployments…