CVE-2026-81930 Apache Airflow Snowflake provider 请求伪造漏洞
影响攻击者可窃取并重放 Snowflake 访问令牌
Apache Airflow 的 Snowflake provider 在将连接的 account 和 region 字段拼接到请求 URL 前未做校验。攻击者可在 account 中注入 /、? 或 # 等字符,把目标域名降级为路径、查询或片段,从而控制请求实际发送的主机。该请求携带由连接私钥签发的 JWT 或 OAuth/程序化访问令牌,导致有效令牌被发送到攻击者指定主机。
影响范围
Apache Airflow 的 Snowflake provider(apache-airflow-providers-snowflake)。具体受影响版本范围暂无公开信息,建议以官方公告为准。
漏洞详情
漏洞类型为服务端请求伪造/令牌泄露(URL 注入)。成因是 provider 直接用未校验的 account、region 值拼接 SQL API、OAuth 令牌请求和 Cortex Agent 的 URL。拥有连接编辑权限但无法读取密钥的用户,可修改连接使请求发往恶意主机,再重放窃得的令牌访问真实 Snowflake 端点。
利用条件与风险
利用前提是攻击者具备 Airflow 连接配置的编辑权限(无需 DAG 编写权限),等待已有 DAG 使用该连接即可触发。实战中可导致 Snowflake 账户令牌泄露与越权访问,CVSS 6.3 属中危。
修复建议
官方修复方案暂无公开信息,建议关注 Apache Airflow Snowflake provider 的安全公告并升级到修复版本。临时缓解措施:限制连接配置编辑权限、审计连接 account/region 字段、轮换可能泄露的 Snowflake 密钥与令牌。
Apache Airflow’s Snowflake provider did not validate the connection’s `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to a path, query or fragment and leaves the attacker in control of the request host.
The provider sends that request with an `Authorization: Bearer` header carrying a JWT minted from the connection’s private key, or the configured OAuth or programmatic access token. A user who can edit the Snowflake connection but cannot read its secrets — Airflow gives connection-configuration users write-only access to stored credentials, and a `private_key_file` lives on the worker rather than in the connection — can therefore cause a valid token for the account to be delivered to a host of their choosing and replay it against the genuine Snowflake endpoint. No Dag-authoring ability is required: the attacker edits the connection and waits for an existing Dag to use it. The same unvalidated value was also used to build the OAuth token-request URL and the Cortex Agent base URL.
Affects deployments where Snowflake connections are editable by users who are not trusted with the connection’s credentials. Users are advised to upgrade to `apache-airflow-providers-snowflake` `6.18.0` or later, which rejects `account` and `region` values containing anything other than letters, digits, `.`, `_` and `-` in every URL the provider builds from them.