CVE-2026-81930: Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain
Apache Airflow's Snowflake provider can leak SQL API bearer tokens off-domain via an unvalidated account field (CVE-2026-81930).
Shahar Epstein disclosed CVE-2026-81930, rated moderate, in the Apache Airflow Snowflake provider. The provider builds Snowflake SQL API URLs as https://{account}.snowflakecomputing.com/api/v2/statements. An account value containing a slash, question mark, or hash can demote the intended domain to a path and redirect the SQL API bearer token off-domain. The post does not report exploitation in the wild.
- CVE-2026-81930 is rated moderate in the Airflow Snowflake provider.
- The account field is interpolated into the Snowflake SQL API hostname.
- Slash, question mark, or hash characters can send the bearer token off-domain.
- The oss-security post does not report in-the-wild exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-819306.3—Airflow Snowflake provider leaks bearer tokens via account URLpublished · Apache Software Foundation apache-airflow-providers-snowflake
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81930 | Airflow Snowflake provider leaks bearer tokens via account URL Apache Airflow’s Snowflake provider, before apache-airflow-providers-snowflake 6.18.0, interpolated the connection’s account and region fields into request URLs without validating them. The SQL API URL is built as https://{account}.snowflakecomputing.com/api/v2/statements, so an account value containing "/", "?", or "#" turns the intended Snowflake host into a path, query, or fragment and sends the request, including an Authorization Bearer JWT or configured OAuth or programmatic access token, to a host the editor chooses; the same unvalidated value was used for the OAuth token-request URL and the Cortex Agent base URL. A user who can edit the Snowflake connection but cannot read its secrets can capture a valid token and replay it against the real Snowflake account, without authoring a Dag and without access to a private_key_file that stays on the worker. Deployments are affected only where Snowflake connections are editable by users who are not trusted with those credentials. No public proof of concept is known, CISA’s KEV catalog does not list it, and there is no report of in-the-wild exploitation; CVSS has not yet been scored. |
Posted by Shahar Epstein on Sep 29 Severity: moderate https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to a path,...
This source does not provide full text. Read it at seclists.org.