CVE-2026-81930: Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain
Apache Airflow's Snowflake provider did not validate the connection's account and region fields before interpolating them into request URLs. The SQL API endpoint is built as https://{account}.snowflakecomputing.com/api/v2/statements, so an account value containing /, ? or # demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host.
The provider sends that request with an Authorization: Bearer header carrying a JWT minted from the connection's private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets — Airflow gives connection-configuration users write-only access to stored credentials, and a privatekeyfile lives on the worker rather than in the connection — can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL.
Affects deployments where Snowflake connections are editable by users who are not trusted with the connection's credentials. Users are advised to upgrade to apache-airflow-providers-snowflake 6.18.0 or later, which rejects account and region values containing anything other than letters, digits, ., and - in every URL the provider builds from them.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
apache-airflow-providers-snowflaketo a version that resolves this vulnerability.Fixed in 6.18.0
Event History
Frequently Asked Questions
Who can exploit this issue in an Airflow deployment?
A user who can edit the Snowflake connection configuration can exploit it, even if they cannot read the connection's stored secrets. They do not need permission to author or modify DAGs; they can wait for an existing DAG to use the altered connection.
What credential could be exposed?
The outbound request carries an Authorization: Bearer token. Depending on the connection configuration, this may be a JWT minted from the connection private key, a configured OAuth token, or a programmatic access token.
Does the attacker need access to the worker-hosted private key?
No. The private_key_file can remain on the worker and does not need to be readable by the attacker. Editing the connection's account value can cause Airflow to mint and send a valid bearer token to an attacker-controlled host.
Which connection fields and request flows are involved?
The unvalidated account and region fields are used when constructing request URLs. In addition to the SQL API endpoint, the same unvalidated value is used for the OAuth token-request URL and the Cortex Agent base URL.