This issue affects Apache Airflow Provider for Databricks: from 1.10.0 before 1.12.0.
Users are recommended to upgrade to version 1.12.0, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wrpj-755p-x363 | Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache airflow Providers Databricks
|
|
| CPEs | cpe:2.3:a:apache:airflow_providers_databricks:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache airflow Providers Databricks
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache airflow Provider For Databricks |
|
| Vendors & Products |
Apache
Apache airflow Provider For Databricks |
Tue, 31 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate certificates for connections to Databricks back-end which could result in a man-of-a-middle attack that traffic is intercepted and manipulated or credentials exfiltrated w/o notice. This issue affects Apache Airflow Provider for Databricks: from 1.10.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which fixes the issue. | |
| Title | Apache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange | |
| Weaknesses | CWE-295 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-03-31T13:31:19.039Z
Reserved: 2026-03-16T10:17:35.548Z
Link: CVE-2026-32794
Updated: 2026-03-30T23:11:36.468Z
Status : Analyzed
Published: 2026-03-30T22:16:18.760
Modified: 2026-04-02T20:26:24.757
Link: CVE-2026-32794
No data.
OpenCVE Enrichment
Updated: 2026-04-03T09:38:00Z
Github GHSA