CVE-2026-49486: Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)
(updated )
The Apache Airflow FTP provider’s FTPSHook.get_conn() created an ftplib.FTP_TLS connection but never called prot_p(), so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using FTPSHook or FTPSFileTransmitOperator to move files over FTPS exposed file contents and credentials-in-transit to a network attacker able to observe the data connection. Upgrade apache-airflow-providers-ftp to 3.15.1 or later, which issues PROT P to encrypt the data channel.
References
- github.com/advisories/GHSA-fgch-86x8-fv43
- github.com/apache/airflow/commit/a929d142d667f71dea29c565a7167216a9c30378
- github.com/apache/airflow/pull/67946
- github.com/apache/airflow/releases/tag/providers-ftp/3.15.1
- github.com/pypa/advisory-database/tree/main/vulns/apache-airflow-providers-ftp/PYSEC-2026-238.yaml
- lists.apache.org/thread/gwnsxlt9hfj5pc543wxtogbnjdn04xj1
- nvd.nist.gov/vuln/detail/CVE-2026-49486
Code Behaviors & Features
Detect and mitigate CVE-2026-49486 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →