{"id":"CVE-2026-81930","published":"2026-09-29T10:17:12.673","lastModified":"2026-09-29T19:17:26.480","description":"Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host.\n\nThe provider sends that request with an `Authorization: Bearer` header carrying a JWT minted from the connection's private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets — Airflow gives connection-configuration users write-only access to stored credentials, and a `private_key_file` lives on the worker rather than in the connection — can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL.\n\nAffects deployments where Snowflake connections are editable by users who are not trusted with the connection's credentials. Users are advised to upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-` in every URL the provider builds from them.","cvssScore":6.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","cwes":["CWE-522"],"vendors":[],"products":[],"references":[{"url":"https://github.com/apache/airflow/pull/72174","tags":[]},{"url":"https://lists.apache.org/thread/324jm2mxd5x4nq85jfw1ostz94xwzrmk","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/09/29/12","tags":[]}],"exploitRefs":[{"url":"https://github.com/apache/airflow/pull/72174","tags":[]}],"hasPoc":true,"ai":null}