Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-39441

20
FAUCET Score

CVE-2023-39441 is a vulnerability affecting Apache Airflow, its SMTP Provider, and IMAP Provider, where the default SSL context failed to validate server X.509 certificates. This flaw, rated Medium severity (CVSS 5.9), could allow an attacker in a Man-in-the-Middle (MITM) position to intercept and disclose mail server credentials or mail contents due to the lack of certificate verification. While the vulnerability is remotely exploitable with high attack complexity, there is currently no evidence of active exploitation, public exploit code, or significant community discussion. Users are advised to upgrade to Apache Airflow 2.7.0+, IMAP Provider 3.3.0+, and SMTP Provider 1.3.0+ to remediate.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.7.0CPE matchmatch criteria
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*
< 3.3.0CPE matchmatch criteria
cpe:2.3:a:apache:apache-airflow-providers-imap:*:*:*:*:*:*:*:*
< 1.3.0CPE matchmatch criteria
cpe:2.3:a:apache:apache-airflow-providers-smtp:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.59%
Probability of exploitation in next 30 days
EPSS Percentile
44.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0059 is in the 7th percentile among its peer group of 19,956 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: apache-airflow-providers-smtpFixed in: 1.3.0
pippatch availablevia ghsa
Product: apache-airflow-providers-imapFixed in: 3.3.0
pippatch availablevia ghsa
Product: apache-airflowFixed in: 2.7.0

Vendor Advisories (1)

pipGHSA-5f35-pq34-c87qmedium

Apache Airflow missing Certificate Validation

Aug 23, 2023

References

github.com / apache/airflow/pull/33070
Patch
github.com / apache/airflow/pull/33075
Patch
github.com / apache/airflow/pull/33108
Patch
lists.apache.org / thread/xzp4wgjg2b1o6ylk2595df8bstlbo1lb
Mailing ListPatchVendor Advisory
openwall.com / lists/oss-security/2023/08/23/2
Mailing ListPatchThird Party Advisory