Posted by Shahar Epstein on Sep 29 Severity: moderate Affected versions: - Apache Airflow Snowflake provider before 6.18.0 Description: Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to a path,...
CVE-2026-81930: Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer token off-domain
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/986
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.




