Improper Input Validation in Apache Airflow's Snowflake Provider
CVE-2026-81930

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-81930?

The Snowflake provider within Apache Airflow has a vulnerability due to improper validation of the connection's account and region fields. This flaw allows an attacker to manipulate these fields and craft URLs that could redirect legitimate SQL API requests to a malicious server, effectively compromising session tokens. Users with the ability to modify Snowflake connections can exploit this issue, as the system erroneously trusts the input for constructing critical URLs. These requests may include authorization credentials, posing a significant risk when user permissions are misconfigured. It is crucial for users to upgrade to version 6.18.0 or later, which enforces strict validation rules to prevent unauthorized access.

Affected Version(s)

Apache Airflow Snowflake provider 0 < 6.18.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claude Security Scans
Jarek Potiuk
.