CVE-2026-32794: Apache Airflow Providers Databricks

Medium severity, CVSS 4.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate certificates for connections to Databricks back-end which could result in a man-of-a-middle attack that traffic is intercepted and manipulated or credentials exfiltrated w/o notice. This issue affects Apache Airflow Provider for Databricks: from 1.10.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which fixes the issue.

Affected products

  • Apache Airflow Providers Databricks: from 1.10.0, before 1.12.0 (fixed in 1.12.0)

Published 2026-03-30. Last modified 2026-06-17.