snowflake-connector-python vulnerabilities
CVEs whose affected-version data names the snowflake-connector-python package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
9 CVEsRSS
CVE-2026-86600High· 8.2In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint
In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify …
CVE-2026-86597Medium· 6.5Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be…
Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be…
CVE-2026-85525High· 7.4Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and def…
Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and def…
CVE-2026-15925CriticalSnowflake Connector for Python improperly verifies TLS hostnames
Snowflake Connector for Python improperly verifies TLS hostnames
CVE-2025-24795Medium· 4.4snowflake-connector-python vulnerable to insecure cache files permissions
snowflake-connector-python vulnerable to insecure cache files permissions
CVE-2025-24794Medium· 6.7snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache
snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache
CVE-2025-24793High· 7.0snowflake-connector-python vulnerable to SQL Injection in write_pandas
snowflake-connector-python vulnerable to SQL Injection in write_pandas
CVE-2024-49750Medium· 5.5The Snowflake Connector for Python stores sensitive data in logs
The Snowflake Connector for Python stores sensitive data in logs
CVE-2022-42965Medium· 5.9snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)
snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)