VDB
Sign up
HIGH7.5

PYSEC-2026-1136

Apache Airflow Drill Provider vulnerable to improper input validation

Quick fix

PYSEC-2026-1136 — apache-airflow-providers-apache-drill: upgrade to the fixed version with the command below.

pip install --upgrade 'apache-airflow-providers-apache-drill>=2.3.2'

Details

Apache Software Foundation's Apache Airflow Drill Provider before 2.3.2 is vulnerable to improper input validation because the host passed in drill connection is not sanitized.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/apache-airflow-providers-apache-drill
Introduced in: 0Fixed in: 2.3.2
Fixpip install --upgrade 'apache-airflow-providers-apache-drill>=2.3.2'

References