MEDIUM6.3
PYSEC-2026-1151
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Quick fix
PYSEC-2026-1151 — apache-airflow-providers-mysql: upgrade to the fixed version with the command below.
pip install --upgrade 'apache-airflow-providers-mysql>=6.2.0'Details
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow MySQL Provider.
When user triggered a DAG with dump_sql or load_sql functions they could pass a table parameter from a UI, that could cause SQL injection by running SQL that was not intended. It could lead to data corruption, modification and others. This issue affects Apache Airflow MySQL Provider: before 6.2.0.
Users are recommended to upgrade to version 6.2.0, which fixes the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/apache-airflow-providers-mysql
Introduced in:
0Fixed in: 6.2.0Fix
pip install --upgrade 'apache-airflow-providers-mysql>=6.2.0'References
- https://nvd.nist.gov/vuln/detail/CVE-2025-27018[ADVISORY]
- https://github.com/apache/airflow/pull/47254[WEB]
- https://github.com/apache/airflow/pull/47255[WEB]
- https://github.com/apache/airflow[PACKAGE]
- https://lists.apache.org/thread/m8ohgkwz4mq9njohf66sjwqjdy28gvzf[WEB]
- http://www.openwall.com/lists/oss-security/2025/03/19/4[WEB]
- https://pypi.org/project/apache-airflow-providers-mysql[PACKAGE]
- https://github.com/advisories/GHSA-hhm6-jjf4-6pm3[ADVISORY]