Apache Airflow 的 Snowflake 提供程序(provider)在将连接配置中的 和 字段插入请求 URL 之前,未对其进行任何验证。SQL API 端点的 URL 格式为 。如果 值中包含 、 或 字符,原本预期的域名部分就会被降级为路径、查询参数或片段标识符(fragment),从而使攻击者能够完全控制请求的实际目标主机。 该提供程序在发送此类请求时,会携带一个 头部,其中包含基于连接私钥签发的 JWT(JSON Web Token),或配置好的 OAuth 令牌/编程访问令牌。 在以下场景中
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Airflow Snowflake provider | < 6.18.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Airflow Snowflake provider | 0 ~ 6.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102496 | Apache XMLSchema: Denial of service through deeply nested schema structures | |
| CVE-2026-91012 | Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalatio | |
| CVE-2026-91048 | Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege esc | |
| CVE-2026-91085 | Apache Karaf: config:install missing ACL entry allows privilege escalation to admin | |
| CVE-2026-92142 | Apache Karaf: Authorization bypass in JMX MBean lifecycle operations | |
| CVE-2026-81914 | Apache Airflow Google provider: Google Drive query injection via unescaped file and folder | |
| CVE-2026-81862 | Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credenti | |
| CVE-2026-86843 | Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute- | |
| CVE-2026-102495 | Apache XMLSchema: Denial of service through unbounded recursion when resolving schema impo | |
| CVE-2026-97395 | Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO req | |
| CVE-2026-102497 | Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker | |
| CVE-2026-66083 | Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasourc | |
| CVE-2026-82804 | Apache DolphinScheduler: Command Injection in the Alert Script Plugin | |
| CVE-2026-81569 | Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized | |
| CVE-2026-78214 | Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths | |
| CVE-2026-71899 | Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to | |
| CVE-2026-71898 | Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute | |
| CVE-2026-71897 | Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and ba |
No comments yet