CVE-2026-81914
Received Received - Intake

SQL Injection via Unsanitized Drive Query in Apache Airflow Google Provider

Vulnerability report for CVE-2026-81914, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Apache Software Foundation

Description

Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the attacker's choosing to the query. The names are frequently not written by the Dag author. In a wildcard `gcs_to_gdrive` transfer they come from the source bucket listing, so anyone able to create objects in that bucket controls them β€” typically an external data producer or an ingest-only service account, a different trust principal from the Dag author. An injected clause can broaden the match and so steer which file or folder the hook resolves: an upload can be directed into a folder the attacker named, and, because downloads select the most recently modified match, a download can return a file they placed rather than the one the Dag asked for. Affects deployments passing externally-sourced names to the Google Drive hook, including wildcard `gcs_to_gdrive` transfers from buckets writable by less-trusted principals. Users are advised to upgrade to `apache-airflow-providers-google` `22.6.0` or later, which escapes quote and backslash characters in every value interpolated into a Drive query.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache apache_airflow_providers_google 22.6.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-943 The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Apache Airflow's Google provider when using Google Drive search. It occurs because file and folder names are directly inserted into single-quoted string literals in Drive queries without escaping special characters like apostrophes. An attacker can exploit this by naming a file or folder with an apostrophe, which breaks the query structure and allows them to manipulate search results. This could redirect file transfers or downloads to unintended locations.

Detection Guidance

Check Apache Airflow versions for the Google provider. Run: pip show apache-airflow-providers-google. If version is below 22.6.0, the system is vulnerable. Inspect DAGs using Google Drive hooks for wildcard transfers from externally writable buckets.

Impact Analysis

If you use Apache Airflow with Google Drive integration and allow external users to create files or folders in a source bucket, an attacker could exploit this to alter file transfers or downloads. They could make your system retrieve or store files in the wrong location, potentially leading to data leaks, corruption, or unauthorized access to sensitive files.

Compliance Impact

This vulnerability could lead to unauthorized access or exposure of sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. For example, if personal or health data is accessed or transferred incorrectly due to the exploit, it could result in non-compliance with data protection standards and potential legal consequences.

Mitigation Strategies

Upgrade the Google provider package to version 22.6.0 or later using: pip install --upgrade apache-airflow-providers-google. Review and restrict write access to source buckets used in wildcard transfers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81914. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart