CVE-2026-86843: Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-cluster example Dag
Apache Airflow Teradata provider before 3.7.0 allows SQL injection via unconstrained example Dag Params.
CVE-2026-86843 is a low-severity SQL injection flaw in the Apache Airflow Teradata provider before version 3.7.0. The compute-cluster example DAG declared every Dag Param as unconstrained free text and templated those values into operators that interpolate them into Teradata DDL. A user allowed to trigger that DAG, a lower-trust role than the DAG author, can abuse the parameters. Shahar Epstein reported the issue to the oss-security list on September 29, 2026.
- Low-severity flaw in the Airflow Teradata provider before 3.7.0.
- The example compute-cluster DAG templates free-text params into Teradata DDL.
- Users permitted to trigger the DAG can inject SQL.
- The DAG author role is more trusted than a user who only triggers it.
Vulnerabilities mentionedAll →
- CVE-2026-868436.3—SQL injection in Airflow Teradata example Dagpublished · Apache Airflow Teradata provider (apache-airflow-providers-teradata) compute-cluster example Dag
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86843 | SQL injection in Airflow Teradata example Dag The Apache Airflow Teradata provider's compute-cluster example Dag treated every Dag Param as unconstrained free text and templated those values into compute-cluster operators that interpolate them into Teradata DDL. A user allowed to trigger the Dag, a lower-trust role that does not need its own Teradata credentials, could inject SQL fragments that run as the task's connection and could point the task at any other connection in the deployment because the connection id was also a free-text Param. Only deployments that run this example Dag, or a Dag copied from it, are affected; the provider's operator code is unchanged. Users should upgrade to apache-airflow-providers-teradata 3.7.0 or later, which constrains Params to validated identifiers and a closed set and removes connection selection and free-form option strings from trigger-time input. No public proof-of-concept is known and the issue is not listed in CISA KEV. |
Posted by Shahar Epstein on Sep 29 Severity: low Affected versions: - Apache Airflow Teradata provider before 3.7.0 Description: The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the Dag author, and one that...
This source does not provide full text. Read it at seclists.org.