{"id":"CVE-2026-81930","title":"Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs","summary":"Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements…","severity":"none","cwe":["CWE-522"],"vendor":"Apache Software Foundation","product":"apache-airflow-providers-snowflake","affected":["apache-airflow-providers-snowflake < 6.18.0"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T10:17:12.673","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81930","references":[{"url":"https://github.com/apache/airflow/pull/72174","label":"security@apache.org"},{"url":"https://lists.apache.org/thread/324jm2mxd5x4nq85jfw1ostz94xwzrmk","label":"security@apache.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T10:31:36.314Z","slug":"CVE-2026-81930","body":"## Overview\n\nApache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host.\n\nThe provider sends that request with an `Authorization: Bearer` header carrying a JWT minted from the connection's private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets — Airflow gives connection-configuration users write-only access to stored credentials, and a `private_key_file` lives on the worker rather than in the connection — can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL.\n\nAffects deployments where Snowflake connections are editable by users who are not trusted with the connection's credentials. Users are advised to upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-` in every URL the provider builds from them.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}