CVE-2026-81930
Received Received - Intake

URL Injection in Apache Airflow Snowflake Provider

Vulnerability report for CVE-2026-81930, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Apache Software Foundation

Description

Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host. The provider sends that request with an `Authorization: Bearer` header carrying a JWT minted from the connection's private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets β€” Airflow gives connection-configuration users write-only access to stored credentials, and a `private_key_file` lives on the worker rather than in the connection β€” can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL. Affects deployments where Snowflake connections are editable by users who are not trusted with the connection's credentials. Users are advised to upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-` in every URL the provider builds from them.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache apache_airflow_providers_snowflake From 6.18.0 (inc)
apache apache_airflow_providers_snowflake 6.18.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Apache Airflow's Snowflake provider did not validate the connection's account and region fields before using them in URLs. This allowed attackers to manipulate URLs by inserting special characters like /, ?, or #, redirecting requests to malicious hosts while using valid authentication tokens.

Detection Guidance

Check Apache Airflow Snowflake provider version. Run: pip show apache-airflow-providers-snowflake. If version is below 6.18.0, the system is vulnerable. Inspect Snowflake connection configurations for account or region fields containing special characters like /, ?, #, or others outside [a-zA-Z0-9._-].

Impact Analysis

An attacker with edit access to Snowflake connections could steal or replay authentication tokens by redirecting requests to their own server. This could lead to unauthorized data access or manipulation without needing to compromise credentials directly.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected versions may face compliance violations due to insufficient access controls.

Mitigation Strategies

Upgrade apache-airflow-providers-snowflake to version 6.18.0 or later. Update all Snowflake connection account and region fields to use only letters, digits, periods, underscores, and hyphens. Restrict edit permissions on Snowflake connections to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-81930. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart