Repository navigation
ReDoS in SparkSubmitHook._mask_cmd() via user-controlled application_args (apache-airflow-providers-apache-spark) #70676
Description
Activity
Thanks for opening your first issue here! Be sure to follow the issue template! If you are willing to raise PR to address this issue please do so, no need to wait for approval.
- addedkind:bugThis is a clearly a bugThis is a clearly a bugsecuritySecurity issues that must be fixedSecurity issues that must be fixed
on Jul 29, 2026 A remote authenticated attacker (Airflow user with trigger permission) can block Airflow worker slots indefinitely by triggering DAG runs with crafted application_args
This maybe(?) a possible bug but this is not a security risk. This report is based on autenticated user with full permissions by design acting as an attacker. This is not valid. This is not a case of malicious actor getting permissions that he shouldn't have.
In any case in the future please do not file security voluntarily publicly. Please read the project security policy and how security reports should be submitted.
- added and removedsecuritySecurity issues that must be fixedSecurity issues that must be fixed
on Jul 30, 2026 If this is a security related issue that should not be opened in public - this is called "irresponsible disclosure" @gnsehfvlr
- changed the title
[-]Security: ReDoS in SparkSubmitHook._mask_cmd() via user-controlled application_args (apache-airflow-providers-apache-spark)[/-][+]ReDoS in SparkSubmitHook._mask_cmd() via user-controlled application_args (apache-airflow-providers-apache-spark)[/+]on Jul 31, 2026 This time I did not hide the issue or it's content becasue if you look at our security model, DOS is almost never considered as a security vulnerability - read the model and find out why.
NEVER EVER IN THE FUTURE use "Security issue" in public issue. This is just plain wrong and violates our security policy. Repeated violation of those policy will casue reporting of such accounts to GitHub and eventually disabling them.
You should check if what you report is a security issue by verifying it against our Security model. If it's not, this is a regular non-security PR you can open - you do not even need to open PR. If you determine - after carefuly reading our model - that it's a security issue - follow our Security Policy to report it.
And if you are using Agents to make reports and PRS - it's still YOUR responsibility to instruct them and review what they are doing so you will bear consequences of them doing so.
Reacted by Aaron ChenHi, I’d like to work on this issue. I plan to replace the backtracking-prone masking logic with a linear-time approach and add regression tests covering large application arguments, existing password and secret masking behavior, and inputs without sensitive values. Is that scope acceptable?
Hi! I'd like to fix the ReDoS in SparkSubmitHook._mask_cmd(). Thanks!
Hi, I'd like to take this one. Planning to fix the ReDoS pattern in
_mask_cmd()by replacing the vulnerable regex with a linear-time approach (or bounding backtracking) and add a regression test with a craftedapplication_argspayload. Will follow up with a PR soon.Hi! I'd like to work on this. I'll reproduce, fix, add a regression test, and run the relevant tests. Please let me know if I can proceed / be assigned.
- added a commit that references this issue
on Oct 4, 2026
ReDoS in
_mask_cmd()via User-Controlledapplication_argsSummary
The
apache-airflow-providers-apache-sparkpackage contains a Regular Expression Denial of Service (ReDoS) vulnerability in theSparkSubmitHook._mask_cmd()method. User-controlled values injected through the Airflow REST API DAG triggerconfparameter are incorporated into a shell command string that is processed by a regex with catastrophic backtracking characteristics, enabling a remote DoS attack.Affected Package
Vulnerability Details
In
airflow/providers/apache/spark/hooks/spark_submit.pyat lines 508–530, the_mask_cmd()method applies the following regex to' '.join(connection_cmd):connection_cmdincludesself._application_args, which is a templated field populated from theapplication_argskey in the DAG triggerconfdict. The nested lookahead(?:(?!\2\s).)*combined with the\S*?quantifier causes quadratic backtracking when the input string is long and does not contain the expected pattern.Timing Evidence
The growth rate is O(n²), consistent with quadratic backtracking.
Attack Vector
An authenticated Airflow user with DAG trigger permissions can invoke the following REST API call:
Where
aaaa...aaaa!is a string of ~50,000 characters not containingsecretorpassword. This causes the Airflow worker process executing the SparkSubmitHook to spin for ~57 seconds per task execution, effectively blocking the worker slot.Proof of Concept
application_argsRemediation
Replace the vulnerable regex with a possessive quantifier or atomic group equivalent, or rewrite the masking logic without a nested lookahead:
The key fix is removing the nested lookahead
(?:(?!\2\s).)*and replacing it with a simple\S+or bounded quantifier that cannot exhibit catastrophic backtracking.