id: PYSEC-2026-1149 published: "2026-07-07T11:45:19.508794Z" modified: "2026-07-07T17:23:42.230995Z" aliases: - CVE-2023-22886 - GHSA-mm87-c3x2-6f89 summary: Apache Airflow JDBC Provider Improper Input Validation vulnerability details: "Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection URL] parameters had no restrictions, which made it possible to implement RCE attacks via different type JDBC drivers, obtain airflow server permission. This issue affects Apache Airflow JDBC Provider: before 4.0.0.\n\n\n" affected: - package: name: apache-airflow-providers-jdbc ecosystem: PyPI purl: pkg:pypi/apache-airflow-providers-jdbc ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 4.0.0 versions: - 1.0.0 - 1.0.0b1 - 1.0.0b2 - 1.0.0rc1 - 1.0.1 - 1.0.1rc1 - 2.0.0 - 2.0.0rc1 - 2.0.0rc2 - 2.0.1 - 2.0.1rc1 - 2.1.0 - 2.1.0rc1 - 2.1.0rc2 - 2.1.1 - 2.1.1rc1 - 2.1.2 - 2.1.2rc1 - 2.1.3 - 2.1.3rc1 - 3.0.0 - 3.0.0rc1 - 3.0.0rc2 - 3.1.0 - 3.1.0rc1 - 3.2.0 - 3.2.0rc1 - 3.2.0rc2 - 3.2.0rc3 - 3.2.1 - 3.2.1rc1 - 3.3.0 - 3.3.0rc1 - 3.3.0rc2 - 3.3.0rc3 - 3.4.0 - 3.4.0rc1 - 3.4.0rc2 - 4.0.0rc1 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2023-22886 - type: PACKAGE url: https://github.com/apache/airflow - type: WEB url: https://lists.apache.org/thread/ynbjwp4n0vzql0xzhog1gkp1ovncf8j3 - type: PACKAGE url: https://pypi.org/project/apache-airflow-providers-jdbc - type: ADVISORY url: https://github.com/advisories/GHSA-mm87-c3x2-6f89 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H