CVE-2026-58065Apache · Apache-airflow-providers-git
Vulnerability data via NVD (ingested)
The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or injecting malicious repository content. Deployments that use the Git DAG bundle or Git provider to clone over SSH with a deploy key are affected. The fix changes the default to verify host keys; upgrade to apache-airflow-providers-git `0.4.1` or later and configure a `known_hosts` file.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-58065product:"Apache Apache-airflow-providers-git"http.html:"Apache-airflow-providers-git"More intel sources (5)
vuln:CVE-2026-58065vulnerabilities.cve_id: CVE-2026-58065CVE-2026-58065CVE-2026-58065"CVE-2026-58065" exploit -site:nvd.nist.gov