CVE-2026-81930
Published:September 29, 2026
Updated:October 09, 2026
Apache Airflow's Snowflake provider did not validate the connection's "account" and "region" fields before interpolating them into request URLs. The SQL API endpoint is built as "https://{account}.snowflakecomputing.com/api/v2/statements", so an "account" value containing "/", "?" or "#" demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host.
The provider sends that request with an "Authorization: Bearer" header carrying a JWT minted from the connection's private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets — Airflow gives connection-configuration users write-only access to stored credentials, and a "private_key_file" lives on the worker rather than in the connection — can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL.
Affects deployments where Snowflake connections are editable by users who are not trusted with the connection's credentials. Users are advised to upgrade to "apache-airflow-providers-snowflake" "6.18.0" or later, which rejects "account" and "region" values containing anything other than letters, digits, ".", "_" and "-" in every URL the provider builds from them.
Affected Packages
apache-airflow-providers-snowflake (CONDA):
Affected version(s) >=4.2.0 <6.18.0Fix Suggestion:
Update to version 6.18.0https://github.com/apache/airflow.git (GITHUB):
Affected version(s) >=providers-snowflake/4.2.0 <providers-snowflake/6.18.0Fix Suggestion:
Update to version providers-snowflake/6.18.0apache-airflow-providers-snowflake (PYTHON):
Affected version(s) >=4.2.0 <6.18.0Fix Suggestion:
Update to version 6.18.0Related Resources (6)
Do you need more information?
Contact UsCVSS v4
Base Score:
5.3
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
LOW
Vulnerable System Availability
LOW
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
6.3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW
Weakness Type (CWE)
Insufficiently Protected Credentials
EPSS
Base Score:
0.43