<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Apache-Airflow-Providers-Sftp on CVE Alert &amp; Security Feed</title><link>https://cvealert.net/products/apache-airflow-providers-sftp/</link><description>Recent content in Apache-Airflow-Providers-Sftp on CVE Alert &amp; Security Feed</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 17 Jun 2026 13:20:47 +0000</lastBuildDate><atom:link href="https://cvealert.net/products/apache-airflow-providers-sftp/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-50203</title><link>https://cvealert.net/posts/cve-2026-50203/</link><pubDate>Wed, 17 Jun 2026 13:20:47 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-50203/</guid><description>A path traversal in the SFTP provider (&lt;code&gt;SFTPHook.retrieve_directory&lt;/code&gt; / &lt;code&gt;SFTPOperator(operation=get)&lt;/code&gt;) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is required — the attack surface is any deployment downloading directories from an untrusted SFTP server. Upgrade &lt;code&gt;apache-airflow-providers-sftp&lt;/code&gt; to 5.8.1 or later.</description></item></channel></rss>