Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-81914— Apache Airflow Google provider: Google Drive query injection via unescaped file and folder names

Quick assessment

Affected
Apache Software Foundation Apache Airflow Google provider
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Airflow 的 Google 提供者(provider)在构建 Google Drive 搜索表达式时,直接将文件和文件夹名称插值到用单引号包裹的字符串字面量中,而未对用于分隔这些字面量的单引号字符进行转义。因此,如果名称中包含撇号(apostrophe,即 ),就会提前终止该字符串字面量,从而允许攻击者向查询中追加其自定义的子句。 这些名称通常并非由 DAG 作者直接编写。在通配符 传输任务中,名称来源于源 GCS 存储桶的对象列表。因此,任何能够在此存储桶中创建对象的主体都能控制这些名称——这

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81914

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Airflow Google provider: Google Drive query injection via unescaped file and folder names
Source: CVE Program / CVE List V5
Vulnerability Description
Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the attacker's choosing to the query. The names are frequently not written by the Dag author. In a wildcard `gcs_to_gdrive` transfer they come from the source bucket listing, so anyone able to create objects in that bucket controls them — typically an external data producer or an ingest-only service account, a different trust principal from the Dag author. An injected clause can broaden the match and so steer which file or folder the hook resolves: an upload can be directed into a folder the attacker named, and, because downloads select the most recently modified match, a download can return a file they placed rather than the one the Dag asked for. Affects deployments passing externally-sourced names to the Google Drive hook, including wildcard `gcs_to_gdrive` transfers from buckets writable by less-trusted principals. Users are advised to upgrade to `apache-airflow-providers-google` `22.6.0` or later, which escapes quote and backslash characters in every value interpolated into a Drive query.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
数据查询逻辑中特殊元素的不当中和
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Airflow Google provider 0 ~ 22.6.0 -

II. Public POCs for CVE-2026-81914

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81914

请登录查看更多情报信息。

Other References for CVE-2026-81914 (2)

Same Patch Batch · Apache Software Foundation · 2026-09-29 · 19 CVEs total

CVE-2026-102496 Apache XMLSchema: Denial of service through deeply nested schema structures
CVE-2026-91012 Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalatio
CVE-2026-91048 Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege esc
CVE-2026-91085 Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
CVE-2026-92142 Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
CVE-2026-81862 Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credenti
CVE-2026-81930 Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer toke
CVE-2026-86843 Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-
CVE-2026-102495 Apache XMLSchema: Denial of service through unbounded recursion when resolving schema impo
CVE-2026-97395 Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO req
CVE-2026-102497 Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker
CVE-2026-66083 Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasourc
CVE-2026-82804 Apache DolphinScheduler: Command Injection in the Alert Script Plugin
CVE-2026-81569 Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized
CVE-2026-78214 Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths
CVE-2026-71899 Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to
CVE-2026-71898 Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute
CVE-2026-71897 Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and ba

IV. Related Vulnerabilities

V. Comments for CVE-2026-81914

No comments yet


Leave a comment