Vulnerability Description
The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or injecting malicious repository content. Deployments that use the Git DAG bundle or Git provider to clone over SSH with a deploy key are affected. The fix changes the default to verify host keys; upgrade to apache-airflow-providers-git `0.4.1` or later and configure a `known_hosts` file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Apache-Airflow-Providers-Git | < 0.4.1 |
Related Weaknesses (CWE)
References
- https://github.com/apache/airflow/pull/69103Issue TrackingPatch
- https://lists.apache.org/thread/fjmclngfksz2kp7llpcjxzdz568h0zhcMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/13/3Mailing ListThird Party Advisory
FAQ
What is CVE-2026-58065?
CVE-2026-58065 is a vulnerability with a CVSS score of 8.1 (HIGH). The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between...
How severe is CVE-2026-58065?
CVE-2026-58065 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-58065?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Apache-Airflow-Providers-Git.