Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41016

25
FAUCET Score

Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between the Airflow worker and the SMTP server could present a self-signed certificate, complete the STARTTLS upgrade, and capture the SMTP credentials sent during the subsequent `login()` call. Users are advised to upgrade to the `apache-airflow-providers-smtp` version that contains the fix.

First published: Apr 30, 2026Last modified: Apr 30, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.0.0, < 3.0.0CPE match
cpe:2.3:a:apache:apache-airflow-providers-smtp:*:rc1:*:*:*:*:*:*
>= 2.0.0, < 3.0.0CPE matchmatch criteria
cpe:2.3:a:apache:airflow:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
18.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 2nd percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: apache-airflow-providers-smtpFixed in: 3.0.0
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

pipGHSA-x8mh-94wc-33gvmedium

apache-airflow-providers-smtp: No certificate validation on SMTP STARTTLS connections in SMTP provider

Apr 30, 2026
apacheapache:www.mail-archive.com/[email protected]/msg11008.htmlLOW

Re: CVE-2026-41016: Apache Airflow SMTP Provider: No certificate validation on SMTP STARTTLS connections

Apr 29, 2026

References

github.com / apache/airflow/pull/65346
Issue TrackingPatch
lists.apache.org / thread/gb202qy5r31bgdd3d51d7s5o1jh40kc4
Mailing ListVendor Advisory