Five Apache Airflow provider flaws span four integrations
Apache disclosed five Airflow provider flaws involving Vault secrets, logged cloud credentials, Drive query injection, a Snowflake token redirect, and example-DAG SQL injection.
Apache disclosed five Airflow provider vulnerabilities on 24 and 29 September 2026: three rated moderate and two rated low. CVE-2026-97636, in HashiCorp provider 4.6.0 before 4.8.0, lets a team-scoped DAG author supply a Variable key containing a path separator so the Vault secrets backend resolves another team's secret; 4.8.0 is the fix for affected multi-team deployments. CVE-2026-81862, fixed in Teradata provider 3.7.0, causes S3ToTeradataOperator and AzureBlobStorageToTeradataOperator to place private source-bucket credentials in SQL text, Airflow task logs, and Teradata query logs. CVE-2026-86843, also fixed in Teradata provider 3.7.0, is low-severity SQL injection because the compute-cluster example DAG templates unconstrained Dag Params into Teradata DDL, which a lower-trust user allowed to trigger that DAG can abuse; Shahar Epstein reported it on 29 September 2026. CVE-2026-81914, fixed in Google provider 22.6.0, lets an apostrophe in a file or folder name terminate a quoted Drive search literal and append attacker-chosen clauses. CVE-2026-81930, disclosed by Shahar Epstein, can redirect a Snowflake SQL API bearer token off-domain when the account field contains a slash, question mark, or hash; the reports give no fixed version, do not disagree, and do not report in-the-wild exploitation for the credential-logging, Drive, or Snowflake issues.
- CVE-2026-97636 (moderate): HashiCorp provider 4.6.0 before 4.8.0 lets a team-scoped DAG author use a Variable key containing a path separator to bypass the Vault team-scope guard; fixed in 4.8.0 for multi-team Vault deployments.
- CVE-2026-81862 (moderate): Teradata provider before 3.7.0; S3ToTeradataOperator and AzureBlobStorageToTeradataOperator embed private source-bucket credentials in SQL text, Airflow task logs, and Teradata query logs; fixed in 3.7.0; no…
- CVE-2026-86843 (low): Teradata provider before 3.7.0; the compute-cluster example DAG templates unconstrained Dag Params into Teradata DDL, so a user allowed to trigger it can inject SQL; Shahar Epstein reported it on 29 September 2026.
- CVE-2026-81914 (low): Google provider before 22.6.0 inserts file and folder names into quoted Drive search literals; an apostrophe can append attacker-chosen clauses; fixed in 22.6.0; no in-the-wild exploitation described.
- CVE-2026-81930 (moderate): Snowflake provider builds https://{account}.snowflakecomputing.com/api/v2/statements; a slash, question mark, or hash in account can send the SQL API bearer token off-domain; disclosed by Shahar Epstein; no fixed…
Coverage timelineoldest first · each row is one article
- · 5d agoCVE-2026-97636: Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key
oss-security· 48
Apache Airflow HashiCorp provider flaw lets a team-scoped DAG author read another team's Vault secret.
- · 18h agoCVE-2026-81862: Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credentials in SQL text, task logs and Teradata query logs
oss-security· 46
Apache Airflow Teradata provider before 3.7.0 embeds cloud storage credentials in SQL and logs (CVE-2026-81862).
- · 18h ago
Vulnerabilities in this storyAll →
- CVE-2026-818626.5—Cloud credential leak in Apache Airflow Teradata providerpublished · Apache Software Foundation apache-airflow-providers-teradata+3 related
- CVE-2026-976366.5—Apache Airflow HashiCorp providerpublished
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected |
|---|