CVE-2022-42965Medium· 5.9▾ Sunlitsnowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.8%
0.8% → 0.9%
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the get_file_transfer_type method.
snowflake-connector-python < 2.8.2Upgrade to a patched release:
snowflake-connector-python 2.8.2Connected by shared product, vendor, weakness, or advisory.
CVE-2025-24795Medium· 4.4snowflake-connector-python vulnerable to insecure cache files permissions
CVE-2025-24794Medium· 6.7snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache
CVE-2024-49750Medium· 5.5The Snowflake Connector for Python stores sensitive data in logs
CVE-2025-24793High· 7.0snowflake-connector-python vulnerable to SQL Injection in write_pandas
CVE-2026-15925CriticalSnowflake Connector for Python improperly verifies TLS hostnames
CVE-2026-85525High· 7.4Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and def…