Posted by Shahar Epstein on Sep 29 Severity: low Affected versions: - Apache Airflow Teradata provider before 3.7.0 Description: The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the Dag author, and one that...
CVE-2026-86843: Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-cluster example Dag
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/987
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.




