logo

CVE-2026-58065: Apache Airflow Git Provider Disables SSH Host Key Verification

ID: af48ecd7-9fb1-5199-97ee-81145fe3a656

STIX ID: report--af48ecd7-9fb1-5199-97ee-81145fe3a656

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

...
...

This advisory describes CVE-2026-58065: the Apache Airflow "apache-airflow-providers-git" provider runs git-over-SSH with StrictHostKeyChecking=no and UserKnownHostsFile=/dev/null by default, which disables SSH host key verification and allows an attacker able to intercept or redirect traffic (ARP/DNS/BGP compromise, network path control) to impersonate Git servers, steal SSH credentials, and deliver malicious DAGs; the report assigns a CVSS 8.1 (High) score, identifies high-risk deployment scenarios (CI/CD, data engineering, multi-tenant clouds), and provides remediation, detection, and post-remediation steps including configuring known_hosts, rotating keys, migrating to HTTPS, and monitoring for anomalous behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.