CVE WATCH / VULNERABILITY DETAIL

CVE-2026-81930

MEDIUMCVSS 6.3NVD feed

Published 29 September 2026 · tracked since 29 September 2026

Description

Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-81930 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-81930

MEDIUMCVSS 6.3NVD feed

Published 29 September 2026 · tracked since 29 September 2026

Description

Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]