CVE-2026-86843: Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-cluster example Dag
Apache Airflow Teradata provider before 3.7.0 allows SQL injection via unconstrained example Dag Params.
CVE-2026-86843 is a low-severity SQL injection flaw in the Apache Airflow Teradata provider before version 3.7.0. The compute-cluster example DAG declared every Dag Param as unconstrained free text and templated those values into operators that interpolate them into Teradata DDL. A user allowed to trigger that DAG, a lower-trust role than the DAG author, can abuse the parameters. Shahar Epstein reported the issue to the oss-security list on September 29, 2026.