PYSEC-2026-4188

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/apache-airflow-providers-snowflake/PYSEC-2026-4188.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-4188
Aliases
Published
2026-09-29T10:17:12Z
Modified
2026-10-08T10:00:03Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

Apache Airflow's Snowflake provider did not validate the connection's account and region fields before interpolating them into request URLs. The SQL API endpoint is built as https://{account}.snowflakecomputing.com/api/v2/statements, so an account value containing /, ? or # demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host.

The provider sends that request with an Authorization: Bearer header carrying a JWT minted from the connection's private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets — Airflow gives connection-configuration users write-only access to stored credentials, and a private_key_file lives on the worker rather than in the connection — can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL.

Affects deployments where Snowflake connections are editable by users who are not trusted with the connection's credentials. Users are advised to upgrade to apache-airflow-providers-snowflake 6.18.0 or later, which rejects account and region values containing anything other than letters, digits, ., _ and - in every URL the provider builds from them.

References

Affected packages

PyPI / apache-airflow-providers-snowflake

Package

Name
apache-airflow-providers-snowflake
View open source insights on deps.dev
Purl
pkg:pypi/apache-airflow-providers-snowflake

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.18.0

Affected versions

1.*
1.0.0b1
1.0.0b2
1.0.0rc1
1.0.0
1.1.0rc1
1.1.0
1.1.1rc1
1.1.1rc2
1.1.1
1.2.0rc1
1.2.0
1.3.0rc1
1.3.0
2.*
2.0.0rc1
2.0.0rc2
2.0.0rc3
2.0.0
2.1.0rc1
2.1.0rc2
2.1.0
2.1.1rc1
2.1.1
2.2.0rc1
2.2.0
2.3.0rc1
2.3.0
2.3.1rc1
2.3.1
2.4.0rc1
2.4.0
2.5.0rc1
2.5.0rc2
2.5.0
2.5.1rc1
2.5.1
2.5.2rc1
2.5.2
2.6.0rc1
2.6.0
2.7.0rc1
2.7.0
3.*
3.0.0rc1
3.0.0rc2
3.0.0
3.1.0rc1
3.1.0
3.2.0rc1
3.2.0rc2
3.2.0rc3
3.2.0
3.3.0rc1
3.3.0
4.*
4.0.0rc1
4.0.0
4.0.1rc2
4.0.1rc3
4.0.1
4.0.2rc1
4.0.2
4.0.3rc1
4.0.3
4.0.4rc1
4.0.4
4.0.5rc1
4.0.5
4.1.0rc1
4.1.0rc2
4.1.0
4.2.0rc1
4.2.0
4.3.0rc2
4.3.0
4.3.1rc1
4.3.1
4.4.0rc1
4.4.0
4.4.1rc1
4.4.1
4.4.2rc1
4.4.2
5.*
5.0.0rc1
5.0.0
5.0.1rc1
5.0.1
5.1.0rc1
5.1.0
5.1.1rc1
5.1.1
5.1.2rc1
5.1.2
5.2.0rc1
5.2.0
5.2.1rc1
5.2.1
5.3.0rc1
5.3.0rc2
5.3.0
5.3.1rc1
5.3.1
5.4.0rc1
5.4.0
5.5.0rc1
5.5.0
5.5.1rc1
5.5.1
5.5.2rc1
5.5.2
5.6.0rc1
5.6.0
5.6.1rc1
5.6.1
5.7.0rc1
5.7.0
5.7.1rc1
5.7.1
5.8.0rc1
5.8.0
5.8.1rc1
5.8.1
6.*
6.0.0rc1
6.0.0rc2
6.0.0
6.1.0rc1
6.1.0
6.1.1rc1
6.1.1
6.2.0rc1
6.2.0
6.2.1rc1
6.2.1
6.2.2rc1
6.2.2
6.3.0rc1
6.3.0rc2
6.3.0
6.3.1rc1
6.3.1
6.4.0rc1
6.4.0
6.5.0rc1
6.5.0
6.5.1rc1
6.5.1
6.5.2rc1
6.5.2
6.5.3rc1
6.5.3
6.5.4rc1
6.5.4
6.6.0rc1
6.6.0
6.6.1rc1
6.6.1
6.7.0rc1
6.7.0
6.8.0rc1
6.8.0
6.8.1rc1
6.8.1
6.8.2rc1
6.8.2
6.9.0rc1
6.9.0
6.9.1rc1
6.9.1
6.10.0rc1
6.10.0
6.11.0rc1
6.11.0
6.12.0rc1
6.12.0
6.12.1rc1
6.12.1
6.12.2rc1
6.12.2
6.13.0rc1
6.13.0
6.14.0rc1
6.14.0
6.15.0rc1
6.15.0rc2
6.15.0
6.16.0rc1
6.16.0rc2
6.16.0
6.16.1rc1
6.16.1
6.17.0rc1
6.17.0
6.18.0rc1

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/apache-airflow-providers-snowflake/PYSEC-2026-4188.yaml"