๐Ÿ” CVE Alert

CVE-2026-81914

UNKNOWN 0.0

Apache Airflow Google provider: Google Drive query injection via unescaped file and folder names

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the attacker's choosing to the query. The names are frequently not written by the Dag author. In a wildcard `gcs_to_gdrive` transfer they come from the source bucket listing, so anyone able to create objects in that bucket controls them โ€” typically an external data producer or an ingest-only service account, a different trust principal from the Dag author. An injected clause can broaden the match and so steer which file or folder the hook resolves: an upload can be directed into a folder the attacker named, and, because downloads select the most recently modified match, a download can return a file they placed rather than the one the Dag asked for. Affects deployments passing externally-sourced names to the Google Drive hook, including wildcard `gcs_to_gdrive` transfers from buckets writable by less-trusted principals. Users are advised to upgrade to `apache-airflow-providers-google` `22.6.0` or later, which escapes quote and backslash characters in every value interpolated into a Drive query.

CWE CWE-943
Vendor apache software foundation
Product apache airflow google provider
Published Sep 29, 2026
Last Updated Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache airflow google provider

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache airflow google provider are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Airflow Google provider
0 < 22.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/airflow/pull/72166 lists.apache.org: https://lists.apache.org/thread/90osv795jrqds051y7v3lcdzhsospooo openwall.com: http://www.openwall.com/lists/oss-security/2026/09/29/13

Credits

Claude Security Scans Jarek Potiuk