---
id: CVE-2023-28707
aliases:
  - GHSA-85pf-r4c7-3j9r
  - PYSEC-2023-3
  - PYSEC-2026-1136
title: 'Apache Airflow Drill Provider vulnerable to improper input validation '
summary: 'Apache Airflow Drill Provider vulnerable to improper input validation '
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
vendor: apache-airflow-providers-apache-drill
product: apache-airflow-providers-apache-drill
ecosystem: pip
affected:
  - apache-airflow-providers-apache-drill < 2.3.2
patched:
  - apache-airflow-providers-apache-drill 2.3.2
published: '2023-04-07'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-85pf-r4c7-3j9r'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-28707'
  - url: 'https://github.com/apache/airflow/pull/30215'
  - url: >-
      https://github.com/apache/airflow/commit/63d9b24aad0b4b9397682ddac1ea5824354789b3
  - url: 'https://github.com/apache/airflow'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2023-3.yaml
  - url: 'https://lists.apache.org/thread/dfoj7q1nd0vhhsl8fjg63z4j6mfmdxtk'
  - url: 'https://www.openwall.com/lists/oss-security/2023/04/07/1'
  - url: 'http://www.openwall.com/lists/oss-security/2023/04/07/1'
tags:
  - osv
  - pip
epss: 0.02062
epssPercentile: 0.80511
ingestedAt: '2026-07-08T18:25:47.304Z'
---

## Overview

Apache Software Foundation's Apache Airflow Drill Provider before 2.3.2 is vulnerable to improper input validation because the host passed in drill connection is not sanitized.

## Affected packages

- `apache-airflow-providers-apache-drill < 2.3.2`

## Remediation

Upgrade to a patched release:

- `apache-airflow-providers-apache-drill 2.3.2`
