Executive brief
Apache Airflow's FTP provider contains a flaw that causes file transfer operations over FTPS to transmit data in cleartext, even though the control channel is encrypted. An attacker positioned to observe network traffic can intercept sensitive files and credentials being transferred between systems. This affects any organization using Airflow to move files over FTPS without additional network protections.
Technical details
The FTPSHook.get_conn() method in apache-airflow-providers-ftp creates an ftplib.FTP_TLS connection to establish a TLS-protected control channel but fails to call prot_p() to enable encryption of the data channel. This is a cleartext transmission vulnerability (CWE-319) affecting the FTPSHook class and dependent operators like FTPSFileTransmitOperator. The attack requires network-level access to observe the unencrypted data connection between client and server; no authentication or user interaction is needed. An attacker can capture file contents and embedded credentials transmitted during file operations. The vulnerability is patched in apache-airflow-providers-ftp version 3.15.1 and later, which issues the PROT P command to encrypt the data channel.
Affected products
- Apache apache-airflow-providers-ftp < 3.15.1
Timeline
- 2026-06-26: disclosed: CVE-2026-49486 and GHSA-fgch-86x8-fv43 disclosed
- 2026-06-16: patched: Patch released in version 3.15.1
References
- https://github.com/apache/airflow/pull/67946
- https://lists.apache.org/thread/gwnsxlt9hfj5pc543wxtogbnjdn04xj1
- http://www.openwall.com/lists/oss-security/2026/06/26/1
- https://github.com/apache/airflow/commit/a929d142d667f71dea29c565a7167216a9c30378
- https://github.com/apache/airflow/releases/tag/providers-ftp/3.15.1