Skip to main content
EPSS 0.2%top 91%

CVE-2026-81914: CWE-943: Improper Neutralization of Special Elements in Data Query Logic in Apache Software Foundation Apache Airflow Google provider

0
High
VulnerabilityCVE-2026-81914cvecve-2026-81914cwe-943
Published: 09/29/2026 (09/29/2026, 09:58:12 UTC)
Source: CVE Database V5
Vendor/Project: Apache Software Foundation
Product: Apache Airflow Google provider

Description

Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the attacker's choosing to the query. The names are frequently not written by the Dag author. In a wildcard `gcs_to_gdrive` transfer they come from the source bucket listing, so anyone able to create objects in that bucket controls them — typically an external data producer or an ingest-only service account, a different trust principal from the Dag author. An injected clause can broaden the match and so steer which file or folder the hook resolves: an upload can be directed into a folder the attacker named, and, because downloads select the most recently modified match, a download can return a file they placed rather than the one the Dag asked for. Affects deployments passing externally-sourced names to the Google Drive hook, including wildcard `gcs_to_gdrive` transfers from buckets writable by less-trusted principals. Users are advised to upgrade to `apache-airflow-providers-google` `22.6.0` or later, which escapes quote and backslash characters in every value interpolated into a Drive query.

Affected software

Apache Software Foundation

Apache Airflow Google provider

Affected versions
>=0 <22.6.0
apache-airflow-providers-google
pkg:pypi/apache-airflow-providers-google
Affected versions
>=0 <22.6.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 10:18:00 UTC

Technical Analysis

CVE-2026-81914 is an injection vulnerability in Apache Airflow's Google provider where Google Drive search expressions are constructed by directly interpolating file and folder names into single-quoted string literals without escaping embedded quote characters. This improper neutralization of special elements (CWE-943) allows an attacker who can create objects in source buckets (such as external data producers or ingest-only service accounts) to manipulate the Drive query logic. By injecting clauses into the query, the attacker can influence which files or folders the hook resolves, potentially redirecting uploads to attacker-named folders and downloads to attacker-controlled files. The vulnerability affects versions of apache-airflow-providers-google prior to 22.6.0. The issue is fixed in version 22.6.0 by escaping quote and backslash characters in all interpolated Drive query values.

Potential Impact

An attacker with the ability to create objects in source buckets used in gcs_to_gdrive transfers can manipulate Google Drive search queries to redirect uploads and downloads to attacker-controlled files or folders. This can lead to unauthorized file placement and retrieval, potentially causing data integrity and confidentiality issues within affected Airflow deployments.

Mitigation Recommendations

Users should upgrade to apache-airflow-providers-google version 22.6.0 or later, which includes proper escaping of quote and backslash characters in Google Drive query values, effectively mitigating this vulnerability. No other mitigation is required if the upgrade is applied.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
apache
Date Reserved
2026-08-27T18:22:42.521Z
State
PUBLISHED

Threat ID: 6abb8ce4f7a7c541062d9043

Added to database: 09/29/2026, 10:03:16 UTC

Last enriched: 09/29/2026, 10:18:00 UTC

Last updated: 09/29/2026, 18:20:13 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses