CVE-2026-32794 PUBLISHED

Apache Airflow Provider for Databricks: TLS Certificate Verification Disabled in Databricks Provider K8s Token Exchange

Assigner: apache
Reserved: 16.03.2026 Published: 30.03.2026 Updated: 31.03.2026

Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate certificates for connections to Databricks back-end which could result in a man-of-a-middle attack that traffic is intercepted and manipulated or credentials exfiltrated w/o notice.

This issue affects Apache Airflow Provider for Databricks: from 1.10.0 before 1.12.0.

Users are recommended to upgrade to version 1.12.0, which fixes the issue.

Product Status

Vendor Apache Software Foundation
Product Apache Airflow Provider for Databricks
Versions Default: unaffected
  • affected from 1.10.0 to 1.12.0 (excl.)

Credits

  • Kai Aizen reporter
  • Marcin Wojtyczka remediation developer

References

Problem Types

  • CWE-295 Improper Certificate Validation CWE