GHSA-5f35-pq34-c87q

    Dashboard / Vulnerabilities / GHSA-5f35-pq34-c87q

    GHSA-5f35-pq34-c87q

    Published: 23 Aug 2023Last Modified: 13 Jul 2026

    Summary: Apache Airflow missing Certificate Validation

    Details: Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 are affected by the Validation of OpenSSL Certificate vulnerability. The default SSL context with SSL library did not check a server's X.509 certificate.  Instead, the code accepted any certificate, which could result in the disclosure of mail server credentials or mail contents when the client connects to an attacker in a MITM position. Users are strongly advised to upgrade to Apache Airflow version 2.7.0 or newer, Apache Airflow IMAP Provider version 3.3.0 or newer, and Apache Airflow SMTP Provider version 1.3.0 or newer to mitigate the risk associated with this vulnerability

    Affected packages

    Package

    Name: apache-airflow-providers-smtp

    Purl: pkg:pypi/apache-airflow-providers-smtp

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.3.0

    Affected versions

    1.0.0
    1.0.0rc1
    1.0.1
    1.0.1rc1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-5f35-pq34-c87q | CVE-DB