Apache Airflow Google Provider Vulnerability in File Name Handling
CVE-2026-81914
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 29 September 2026
What is CVE-2026-81914?
A vulnerability exists in the Google provider of Apache Airflow that allows for unsafe interpolation of file and folder names directly into SQL-like queries. This occurs when names sourced from external contributors are processed without proper escaping, leaving them open to manipulation. An attacker could craft a name containing special characters, leading to unauthorized queries that modify the intended file operations. Particularly in scenarios involving wildcard-based transfers to Google Drive, an attacker with write access to the source bucket can exploit this flaw, steering file operations to their advantage by directing uploads to maliciously named folders or fetching unwanted files during downloads. Users are recommended to upgrade to version 22.6.0 or later, which implements necessary sanitization to mitigate this vulnerability.
Affected Version(s)
Apache Airflow Google provider 0 < 22.6.0