Skip to content

CVE-2026-8838 does not yet appear in the GitHub Advisory Database #7809

@stew-larsen

Description

@stew-larsen

CVE-2026-8838 does not yet appear in the GitHub Advisory Database. The
query https://github.com/advisories?query=CVE-2026-8838 returns no
results as of 2026-05-25, seven days after AWS published the bulletin.

Details:

Impact / why this matters: redshift-connector is a transitive
dependency of apache-airflow-providers-amazon, so a large number of
Airflow deployments are exposed. Without a GHSA entry, Dependabot does
not flag affected installations, which is blocking downstream
remediation tracking.

Could this CVE be ingested and a GHSA assigned? Happy to provide any
additional context.

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions