{"id":"PYSEC-2026-2357","summary":"Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange","details":"Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate certificates for connections to Databricks back-end which could result in a man-of-a-middle attack that traffic is intercepted and manipulated or credentials exfiltrated w/o notice.\n\nThis issue affects Apache Airflow Provider for Databricks: from 1.10.0 before 1.12.0.\n\nUsers are recommended to upgrade to version 1.12.0, which fixes the issue.","aliases":["CVE-2026-32794","GHSA-wrpj-755p-x363"],"modified":"2026-07-13T16:31:37.652439075Z","published":"2026-07-13T14:36:45.949510Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32794"},{"type":"WEB","url":"https://github.com/apache/airflow/pull/63704"},{"type":"PACKAGE","url":"https://github.com/apache/airflow"},{"type":"WEB","url":"https://lists.apache.org/thread/hn17yqsgsdtl81llvhf80rkp53hnz5nb"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/03/30/9"},{"type":"PACKAGE","url":"https://pypi.org/project/apache-airflow"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wrpj-755p-x363"}],"affected":[{"package":{"name":"apache-airflow","ecosystem":"PyPI","purl":"pkg:pypi/apache-airflow"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.10.0"},{"fixed":"1.12.0"}]}],"versions":["1.10.0","1.10.1","1.10.10","1.10.10rc1","1.10.10rc2","1.10.10rc3","1.10.10rc4","1.10.10rc5","1.10.11","1.10.11rc1","1.10.11rc2","1.10.12","1.10.12rc1","1.10.12rc2","1.10.12rc3","1.10.12rc4","1.10.13","1.10.13rc1","1.10.14","1.10.14rc1","1.10.14rc2","1.10.14rc3","1.10.14rc4","1.10.15","1.10.15rc1","1.10.1b1","1.10.1rc2","1.10.2","1.10.2b2","1.10.2rc1","1.10.2rc2","1.10.2rc3","1.10.3","1.10.3b1","1.10.3b2","1.10.3rc1","1.10.3rc2","1.10.4","1.10.4b2","1.10.4rc1","1.10.4rc2","1.10.4rc3","1.10.4rc4","1.10.4rc5","1.10.5","1.10.5rc1","1.10.6","1.10.6rc1","1.10.6rc2","1.10.7","1.10.7rc1","1.10.7rc2","1.10.7rc3","1.10.8","1.10.8rc1","1.10.9","1.10.9rc1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/apache-airflow/PYSEC-2026-2357.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}