B3NCLOUD ARTICLE INTELLIGENCE

ARTICLEVIEW

Zurück zu News

[Unknown] CVE-2026-49818 – The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names...

Unknown CVE-2026-49818 The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able to write objects...

Original-Artikel öffnen Zurück zur Übersicht