Apache Airflow Google Provider Vulnerability in File Name Handling
CVE-2026-81914

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-81914?

A vulnerability exists in the Google provider of Apache Airflow that allows for unsafe interpolation of file and folder names directly into SQL-like queries. This occurs when names sourced from external contributors are processed without proper escaping, leaving them open to manipulation. An attacker could craft a name containing special characters, leading to unauthorized queries that modify the intended file operations. Particularly in scenarios involving wildcard-based transfers to Google Drive, an attacker with write access to the source bucket can exploit this flaw, steering file operations to their advantage by directing uploads to maliciously named folders or fetching unwanted files during downloads. Users are recommended to upgrade to version 22.6.0 or later, which implements necessary sanitization to mitigate this vulnerability.

Affected Version(s)

Apache Airflow Google provider 0 < 22.6.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claude Security Scans
Jarek Potiuk
.