GHSA-fgch-86x8-fv43HighCVSS 7.5
Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)
🔗 CVE IDs covered (1)
📋 Description
The Apache Airflow FTP provider's FTPSHook.get_conn() created an ftplib.FTP_TLS connection but never called prot_p(), so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using FTPSHook or FTPSFileTransmitOperator to move files over FTPS exposed file contents and credentials-in-transit to a network attacker able to observe the data connection. Upgrade apache-airflow-providers-ftp to 3.15.1 or later, which issues PROT P to encrypt the data channel.
🎯 Affected products1
- pip/apache-airflow-providers-ftp:< 3.15.1
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-49486
- https://github.com/apache/airflow/pull/67946
- https://lists.apache.org/thread/gwnsxlt9hfj5pc543wxtogbnjdn04xj1
- http://www.openwall.com/lists/oss-security/2026/06/26/1
- https://github.com/apache/airflow/commit/a929d142d667f71dea29c565a7167216a9c30378
- https://github.com/apache/airflow/releases/tag/providers-ftp/3.15.1
- https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow-providers-ftp/PYSEC-2026-238.yaml
- https://github.com/advisories/GHSA-fgch-86x8-fv43