VulnSea

net.snowflake:snowflake-jdbc-fips vulnerabilities

CVEs whose affected-version data names the net.snowflake:snowflake-jdbc-fips package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-86600High· 8.2
1w ago

In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint

In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify …

TwilightSnowflake · snowflake-connector-pythonEPSS 0.31%via NVD
CVE-2026-86597Medium· 6.5
1w ago

Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be…

Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be…

SunlitSnowflake · snowflake-connector-pythonEPSS 0.09%via NVD
CVE-2026-85528Medium· 5.3
2w ago

Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to an attacker-selected HTTPS endpoint

Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to an attacker-selected HTTPS endpoint. An attacker …

SunlitSnowflake · net.snowflake:snowflake-jdbcEPSS 0.18%via NVD
CVE-2026-85525High· 7.4
2w ago

Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and def…

Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and def…

TwilightSnowflake · snowflake-connector-pythonEPSS 0.10%via NVD
net.snowflake:snowflake-jdbc-fips vulnerabilities (CVEs) · VulnSea