CVE-2026-49297 | Apache Airflow Google Provider up to 22.2.0 SFTP File path traversal

SecurityVulns

A vulnerability, which was classified as critical, has been found in Apache Airflow Google Provider up to 22.2.0. Affected is an unknown function of the component SFTP File Handler. Performing a manipulation results in path traversal.

This vulnerability is cataloged as CVE-2026-49297. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More