HIGH7.5
PYSEC-2026-1141
Apache Airflow Spark Provider Improper Input Validation vulnerability
Quick fix
PYSEC-2026-1141 — apache-airflow-providers-apache-spark: upgrade to the fixed version with the command below.
pip install --upgrade 'apache-airflow-providers-apache-spark>=4.1.3'Details
Apache Airflow Spark Provider, versions before 4.1.3, is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection giving an opportunity to read files on the Airflow server. It is recommended to upgrade to a version that is not affected.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/apache-airflow-providers-apache-spark
Introduced in:
0Fixed in: 4.1.3Fix
pip install --upgrade 'apache-airflow-providers-apache-spark>=4.1.3'References
- https://nvd.nist.gov/vuln/detail/CVE-2023-40272[ADVISORY]
- https://lists.apache.org/thread/t03gktyzyor20rh06okd91jtqmw6k1l7[WEB]
- http://www.openwall.com/lists/oss-security/2023/08/17/1[WEB]
- http://www.openwall.com/lists/oss-security/2023/08/18/1[WEB]
- https://pypi.org/project/apache-airflow-providers-apache-spark[PACKAGE]
- https://github.com/advisories/GHSA-r2f6-6928-fh8f[ADVISORY]