Improper Neutralization of Special Elements in Data Query Logic Affecting apache-airflow-providers-google package, versions [,22.6.0rc1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.29% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWPROVIDERSGOOGLE-20257413
  • published29 Sept 2026
  • disclosed29 Sept 2026

Introduced: 29 Sep 2026

NewCVE-2026-81914  (opens in a new tab)
CWE-943  (opens in a new tab)

How to fix?

Upgrade apache-airflow-providers-google to version 22.6.0rc1 or higher.

Overview

apache-airflow-providers-google is a Provider for Apache Airflow. Implements apache-airflow-providers-google package

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Data Query Logic via GoogleDriveHook in drive.py, where folder names, file names, and folder IDs are interpolated directly into Google Drive q= query string literals without escaping. The Drive query language uses single quotes to delimit string literals and requires backslash-escaping of ' and \, but neither _ensure_folders_exists nor get_file_id applied any escaping before constructing expressions such as name='<folder>' and '<parent>' in parents. An attacker, or ordinary input containing a single quote, can cause the composed query expression to be malformed, resulting in the search not matching the intended target and potentially returning unintended results or bypassing expected access controls. Because object names routinely arrive from bucket listings rather than being written by hand, a quote in a name is ordinary input rather than a special case.

CVSS Base Scores

version 4.0
version 3.1