CVE-2023-22886: Apache Apache-Airflow-Providers-Jdbc

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow JDBC Provider. Airflow JDBC Provider Connection’s [Connection URL] parameters had no restrictions, which made it possible to implement RCE attacks via different type JDBC drivers, obtain airflow server permission. This issue affects Apache Airflow JDBC Provider: before 4.0.0.

Affected products

  • Apache Apache-Airflow-Providers-Jdbc: before 4.0.0 (fixed in 4.0.0)

Published 2023-06-29. Last modified 2026-06-17.