---
id: CVE-2023-40272
aliases:
  - GHSA-r2f6-6928-fh8f
  - PYSEC-2026-1141
title: Apache Airflow Spark Provider Improper Input Validation vulnerability
summary: Apache Airflow Spark Provider Improper Input Validation vulnerability
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
vendor: apache-airflow-providers-apache-spark
product: apache-airflow-providers-apache-spark
ecosystem: pip
affected:
  - apache-airflow-providers-apache-spark < 4.1.3
patched:
  - apache-airflow-providers-apache-spark 4.1.3
published: '2023-08-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-r2f6-6928-fh8f'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-40272'
  - url: 'https://lists.apache.org/thread/t03gktyzyor20rh06okd91jtqmw6k1l7'
  - url: 'http://www.openwall.com/lists/oss-security/2023/08/17/1'
  - url: 'http://www.openwall.com/lists/oss-security/2023/08/18/1'
tags:
  - osv
  - pip
epss: 0.02144
epssPercentile: 0.81302
ingestedAt: '2026-07-08T18:25:52.603Z'
---

## Overview

Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server.
It is recommended to upgrade to a version that is not affected.

## Affected packages

- `apache-airflow-providers-apache-spark < 4.1.3`

## Remediation

Upgrade to a patched release:

- `apache-airflow-providers-apache-spark 4.1.3`
