๐Ÿ” CVE Alert

CVE-2026-81930

UNKNOWN 0.0

Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host. The provider sends that request with an `Authorization: Bearer` header carrying a JWT minted from the connection's private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets โ€” Airflow gives connection-configuration users write-only access to stored credentials, and a `private_key_file` lives on the worker rather than in the connection โ€” can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL. Affects deployments where Snowflake connections are editable by users who are not trusted with the connection's credentials. Users are advised to upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-` in every URL the provider builds from them.

CWE CWE-522
Vendor apache software foundation
Product apache airflow snowflake provider
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache airflow snowflake provider

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache airflow snowflake provider are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Airflow Snowflake provider
0 < 6.18.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apache/airflow/pull/72174 lists.apache.org: https://lists.apache.org/thread/324jm2mxd5x4nq85jfw1ostz94xwzrmk openwall.com: http://www.openwall.com/lists/oss-security/2026/09/29/12

Credits

Claude Security Scans Jarek Potiuk