CVE-2026-58065: Apache Airflow Git Provider Disables SSH Host Key Verification
ID: af48ecd7-9fb1-5199-97ee-81145fe3a656
STIX ID: report--af48ecd7-9fb1-5199-97ee-81145fe3a656
Feed Name: CosmicBytez Labs
This advisory describes CVE-2026-58065: the Apache Airflow "apache-airflow-providers-git" provider runs git-over-SSH with StrictHostKeyChecking=no and UserKnownHostsFile=/dev/null by default, which disables SSH host key verification and allows an attacker able to intercept or redirect traffic (ARP/DNS/BGP compromise, network path control) to impersonate Git servers, steal SSH credentials, and deliver malicious DAGs; the report assigns a CVSS 8.1 (High) score, identifies high-risk deployment scenarios (CI/CD, data engineering, multi-tenant clouds), and provides remediation, detection, and post-remediation steps including configuring known_hosts, rotating keys, migrating to HTTPS, and monitoring for anomalous behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
