Description
Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host.

The provider sends that request with an `Authorization: Bearer` header carrying a JWT minted from the connection's private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets — Airflow gives connection-configuration users write-only access to stored credentials, and a `private_key_file` lives on the worker rather than in the connection — can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL.

Affects deployments where Snowflake connections are editable by users who are not trusted with the connection's credentials. Users are advised to upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-` in every URL the provider builds from them.
Published: 2026-09-29
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Theft via Unvalidated Redirects
Action: Immediate Patch
AI Analysis

Impact

The Snowflake provider for Apache Airflow fails to validate the `account` and `region` fields before inserting them into request URLs. An attacker who can edit a Snowflake connection can supply a value containing characters such as `/`, `?`, or `#`, causing the provider to build a request that redirects to an attacker‑controlled host while still sending a valid bearer token. This token is generated from private key, OAuth, or programmatic credentials and is included in the `Authorization: Bearer` header, effectively allowing the attacker to reuse it against the legitimate Snowflake service or to exfiltrate data. The result is uncontrolled disclosure of secret tokens and potential unauthorized access to the Snowflake account. This issue is classified as CWE-522.

Affected Systems

This issue, identified as CWE-522, affects deployments of the Apache Airflow Snowflake provider, specifically any installation using versions before 6.18.0 of `apache-airflow-providers-snowflake`. The vulnerability is exploitable in environments where users are granted permission to edit Snowflake connections but do not have read access to the stored credentials, allowing them to alter the `account` and `region` values. Users are advised to upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-` in every URL the provider builds from them.

Risk and Exploitability

The EPSS score for this vulnerability is not available, and it is not listed in the CISA KEV catalog. The CVSS score of 6.3 indicates a moderate impact, reflecting the potential for credential compromise without host compromise. The attacker can transmit a valid bearer token to an arbitrary host and replay it against the real Snowflake endpoint, providing unauthorized access. This requires only edit rights to a Snowflake connection, a permission that may be loosely enforced. Consequently, the overall risk to affected systems is high due to the ease of exploitation and the sensitivity of the exposed tokens.

Generated by OpenCVE AI on September 30, 2026 at 04:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to apache-airflow-providers-snowflake 6.18.0 or newer, which validates `account` and `region` input against a restricted character set and addresses the CWE‑522 flaw.
  • Limit Snowflake connection edit permissions to trusted administrators and remove write‑only access from users who do not need to modify connection settings to mitigate the CWE‑522 risk.
  • After applying the patch, revoke any access tokens that may have been exposed by the vulnerability and rotate the associated private keys or OAuth credentials to prevent further credential theft.

Generated by OpenCVE AI on September 30, 2026 at 04:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host. The provider sends that request with an `Authorization: Bearer` header carrying a JWT minted from the connection's private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets — Airflow gives connection-configuration users write-only access to stored credentials, and a `private_key_file` lives on the worker rather than in the connection — can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL. Affects deployments where Snowflake connections are editable by users who are not trusted with the connection's credentials. Users are advised to upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-` in every URL the provider builds from them.
Title Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain
Weaknesses CWE-522
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-29T18:29:50.020Z

Reserved: 2026-08-27T18:42:14.105Z

Link: CVE-2026-81930

cve-icon Vulnrichment

Updated: 2026-09-29T11:08:16.121Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T10:17:12.673

Modified: 2026-09-29T19:17:26.480

Link: CVE-2026-81930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T04:15:08Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials