Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-81930— Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain

Quick assessment

Affected
Apache Software Foundation Apache Airflow Snowflake provider
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Airflow 的 Snowflake 提供程序(provider)在将连接配置中的 和 字段插入请求 URL 之前,未对其进行任何验证。SQL API 端点的 URL 格式为 。如果 值中包含 、 或 字符,原本预期的域名部分就会被降级为路径、查询参数或片段标识符(fragment),从而使攻击者能够完全控制请求的实际目标主机。 该提供程序在发送此类请求时,会携带一个 头部,其中包含基于连接私钥签发的 JWT(JSON Web Token),或配置好的 OAuth 令牌/编程访问令牌。 在以下场景中

AI Predicted 7.5 Difficulty: Moderate

Affected Version Matrix 1

VendorProduct Version RangeStatus
Apache Software Foundation Apache Airflow Snowflake provider < 6.18.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81930

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain
Source: CVE Program / CVE List V5
Vulnerability Description
Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host. The provider sends that request with an `Authorization: Bearer` header carrying a JWT minted from the connection's private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets — Airflow gives connection-configuration users write-only access to stored credentials, and a `private_key_file` lives on the worker rather than in the connection — can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL. Affects deployments where Snowflake connections are editable by users who are not trusted with the connection's credentials. Users are advised to upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-` in every URL the provider builds from them.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的凭证保护机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Airflow Snowflake provider 0 ~ 6.18.0 -

II. Public POCs for CVE-2026-81930

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81930

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-81930 (1)

Mailing List Discussions for CVE-2026-81930 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-29 · 19 CVEs total

CVE-2026-102496 Apache XMLSchema: Denial of service through deeply nested schema structures
CVE-2026-91012 Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalatio
CVE-2026-91048 Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege esc
CVE-2026-91085 Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
CVE-2026-92142 Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
CVE-2026-81914 Apache Airflow Google provider: Google Drive query injection via unescaped file and folder
CVE-2026-81862 Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credenti
CVE-2026-86843 Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-
CVE-2026-102495 Apache XMLSchema: Denial of service through unbounded recursion when resolving schema impo
CVE-2026-97395 Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO req
CVE-2026-102497 Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker
CVE-2026-66083 Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasourc
CVE-2026-82804 Apache DolphinScheduler: Command Injection in the Alert Script Plugin
CVE-2026-81569 Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized
CVE-2026-78214 Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths
CVE-2026-71899 Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to
CVE-2026-71898 Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute
CVE-2026-71897 Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and ba

IV. Related Vulnerabilities

V. Comments for CVE-2026-81930

No comments yet


Leave a comment