The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
CVE-2026-81930: Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-81930
- Published
- Record updated
Summary
CVE-2026-81930 affects Apache Airflow's Snowflake provider, which did not validate the connection's `account` and `region` fields before placing them into request URLs. A value containing `/`, `?` or `#` redirects the SQL API request to an attacker-chosen host, which receives a valid Bearer token minted for the account. A user who can edit a Snowflake connection without reading its secrets can trigger this when an existing Dag uses that connection.
Mitigation
Upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-`.