CVE-2026-81930 Overview
CVE-2026-81930 affects the Apache Airflow Snowflake provider. The provider did not validate the connection's account and region fields before interpolating them into request URLs. An attacker who can edit a Snowflake connection but cannot read its secrets can inject characters such as /, ?, or # into the account field to redirect authenticated requests to a host they control. The redirected request carries a valid Authorization: Bearer token minted from the connection's private key, OAuth token, or programmatic access token. The captured token can then be replayed against the genuine Snowflake endpoint [CWE-522].
Critical Impact
An Airflow user with connection-edit rights but no credential-read access can exfiltrate valid Snowflake bearer tokens and impersonate the account against Snowflake.
Affected Products
- Apache Airflow Snowflake provider (apache-airflow-providers-snowflake) versions prior to 6.18.0
- Snowflake SQL API integrations built via the provider
- Snowflake OAuth token-request and Cortex Agent integrations built via the provider
Discovery Timeline
- 2026-09-29 - CVE-2026-81930 published to the National Vulnerability Database (NVD)
- 2026-09-29 - Last updated in NVD database
Technical Details for CVE-2026-81930
Vulnerability Analysis
The Snowflake provider constructs its SQL API endpoint using string interpolation: https://{account}.snowflakecomputing.com/api/v2/statements. When the account value contains a URL structural character, the parser reinterprets the intended snowflakecomputing.com hostname as a path, query string, or fragment. The effective request host becomes attacker-controlled.
The provider sends this request with an Authorization: Bearer header. The token is minted from the connection's private key file on the worker, or from a configured OAuth or programmatic access token. Because Airflow grants connection-editing users write-only access to stored credentials, and because private_key_file lives on the worker rather than in the connection payload, an attacker who can edit the connection cannot read the secret directly. Redirecting the request to a controlled host lets the attacker capture the token from the Authorization header and replay it against Snowflake.
The same unvalidated account and region values were used to build the OAuth token-request URL and the Cortex Agent base URL, extending the attack surface beyond the SQL API.
Root Cause
The provider treats account and region as opaque strings and inserts them into URLs without validating the character set. There is no allowlist restricting these fields to hostname-safe characters. Any structural URL delimiter injected into account shifts the authoritative host component of the constructed URL.
Attack Vector
Exploitation requires an authenticated Airflow user with permission to edit a Snowflake connection. No DAG-authoring ability is needed. The attacker modifies the account field to a value such as attacker.example.com/x? so the constructed URL resolves to the attacker's host. The attacker then waits for an existing DAG to trigger a task using the connection. The task delivers a valid bearer token to the attacker, who replays it against the real snowflakecomputing.com endpoint to execute queries as the account.
See the GitHub Pull Request for Airflow and the Apache Mailing List Discussion for technical details.
Detection Methods for CVE-2026-81930
Indicators of Compromise
- Snowflake connection records whose account or region fields contain characters outside letters, digits, ., _, and - — particularly /, ?, #, @, or :.
- Outbound HTTPS requests from Airflow workers to hostnames that do not end in snowflakecomputing.com but originate from Snowflake provider tasks.
- Recent audit-log entries showing connection edits by users who do not normally administer Snowflake credentials.
Detection Strategies
- Query the Airflow metadata database for Snowflake connections and validate each account/region value against the allowlist [A-Za-z0-9._-]+.
- Review Airflow audit logs for connection.edit events on Snowflake connections and correlate with subsequent DAG runs using those connections.
- Inspect worker egress traffic and flag TLS SNI values from Snowflake provider processes that resolve to non-Snowflake hosts.
Monitoring Recommendations
- Alert on any modification to Snowflake connection objects by non-privileged accounts.
- Baseline Airflow worker outbound destinations and alert on new hostnames contacted by Snowflake provider tasks.
- Monitor Snowflake account activity for logins or SQL API calls originating from unexpected IP addresses that reuse recent JWTs.
How to Mitigate CVE-2026-81930
Immediate Actions Required
- Upgrade apache-airflow-providers-snowflake to version 6.18.0 or later, which enforces character-set validation on account and region in every URL the provider builds.
- Audit all existing Snowflake connections and normalize any account or region value that contains characters outside [A-Za-z0-9._-].
- Rotate Snowflake private keys, OAuth client secrets, and programmatic access tokens used by any connection that may have been edited by an untrusted user.
Patch Information
The fix is delivered in apache-airflow-providers-snowflake6.18.0. The patched provider rejects account and region values containing anything other than letters, digits, ., _, and - when constructing the SQL API URL, the OAuth token-request URL, and the Cortex Agent base URL. Refer to the GitHub Pull Request for Airflow and the Openwall OSS-Security Update for full change details.
Workarounds
- Restrict the Airflow role that grants connection-edit permission to trusted administrators who are already authorized to view Snowflake credentials.
- Enforce egress filtering on Airflow workers so that Snowflake provider traffic can only reach *.snowflakecomputing.com.
- Implement a pre-commit or CI check that validates connection definitions against the [A-Za-z0-9._-]+ allowlist before deployment.
# Upgrade the Snowflake provider on all Airflow workers and schedulers
pip install --upgrade 'apache-airflow-providers-snowflake>=6.18.0'
# Validate existing Snowflake connections for unsafe characters
airflow connections list --output json \
| jq -r '.[] | select(.conn_type=="snowflake") | .conn_id + " " + (.extra // "")' \
| grep -E '[^A-Za-z0-9._\-" :,{}]'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.