SQL Injection Affecting apache-airflow-providers-teradata package, versions [0,3.7.0rc1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.39% (31st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about SQL Injection vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-APACHEAIRFLOWPROVIDERSTERADATA-20251963
  • published29 Sept 2026
  • disclosed29 Sept 2026
  • creditAndrew Rukin, Jarek Potiuk

Introduced: 29 Sep 2026

NewCVE-2026-86843  (opens in a new tab)
CWE-89  (opens in a new tab)

How to fix?

Upgrade apache-airflow-providers-teradata to version 3.7.0rc1 or higher.

Overview

apache-airflow-providers-teradata is a Provider package apache-airflow-providers-teradata for Apache Airflow

Affected versions of this package are vulnerable to SQL Injection in the Teradata compute-cluster example DAG, where user-settable Params are not properly constrained, allowing an attacker to supply arbitrary values through those parameters. This lack of validation can lead to unintended behavior or abuse of the DAG execution context.

CVSS Base Scores

version 4.0
version 3.1