Vulnerability  ·  2026-09-30

Apache Airflow Snowflake provider lets low-privilege connection editors exfiltrate valid Snowflake JWTs to attacker-controlled hosts

VulnerabilityMedium impactGlobalCVE-2026-81930
NVD published CVE-2026-81930 (CVSS 6.3) on 2026-09-29. The Airflow Snowflake provider interpolated unvalidated account/region fields into request URLs (also the OAuth token-request URL and the Cortex Agent base URL), exfiltrating valid credentials. Fix in provider 6.18.0, which restricts account/region values to letters, digits, '.', '_', and '-' in every URL built from them.
Airflow is core ML/data pipeline orchestration and Snowflake is a primary AI/analytics data platform; the Snowflake provider is how Data/GenAI pipelines talk to cloud warehouses. The flaw lets a user who can edit a connection but not read its secrets steal a live Snowflake JWT and impersonate the pipeline to the data platform — credential theft across the ML pipeline trust boundary, with no DAG-authoring rights required.
A user with edit rights on a Snowflake Airflow connection (but not secret-read rights) sets account/region to a value containing '/', '?' or '#'; the provider builds the SQL API URL as https://{account}.snowflakecomputing.com/api/v2/statements, demoting the intended host and sending the Authorization: Bearer JWT (minted from the connection private key / OAuth token) to the attacker's host, which replays it against the genuine Snowflake endpoint.
apache-airflow-providers-snowflake before 6.18.0
Upgrade apache-airflow-providers-snowflake to 6.18.0 or later; rotate potentially-exposed Snowflake JWT/private keys; restrict connection-edit rights to credential owners.
NVD CVE-2026-81930Apache Airflow PR #72174oss-security advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →