VulnSea

snowflake-connector-python vulnerabilities

CVEs whose affected-version data names the snowflake-connector-python package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2026-86600High· 8.2
2w ago

In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint

In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify …

TwilightSnowflake · snowflake-connector-pythonEPSS 0.31%via NVD
CVE-2026-86597Medium· 6.5
2w ago

Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be…

Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be…

SunlitSnowflake · snowflake-connector-pythonEPSS 0.09%via NVD
CVE-2026-85525High· 7.4
2w ago

Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and def…

Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and def…

TwilightSnowflake · snowflake-connector-pythonEPSS 0.10%via NVD
CVE-2026-15925Critical
2mo ago

Snowflake Connector for Python improperly verifies TLS hostnames

Snowflake Connector for Python improperly verifies TLS hostnames

Midnightsnowflake-connector-python · snowflake-connector-pythonEPSS 0.29%via OSV
CVE-2025-24795Medium· 4.4
1y ago

snowflake-connector-python vulnerable to insecure cache files permissions

snowflake-connector-python vulnerable to insecure cache files permissions

Sunlitsnowflake-connector-python · snowflake-connector-pythonEPSS 0.14%via OSV
CVE-2025-24794Medium· 6.7
1y ago

snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache

snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache

Sunlitsnowflake-connector-python · snowflake-connector-pythonEPSS 0.25%via OSV
CVE-2025-24793High· 7.0
1y ago

snowflake-connector-python vulnerable to SQL Injection in write_pandas

snowflake-connector-python vulnerable to SQL Injection in write_pandas

Twilightsnowflake-connector-python · snowflake-connector-pythonEPSS 0.31%via OSV
CVE-2024-49750Medium· 5.5
1y ago

The Snowflake Connector for Python stores sensitive data in logs

The Snowflake Connector for Python stores sensitive data in logs

Sunlitsnowflake-connector-python · snowflake-connector-pythonEPSS 0.20%via OSV
CVE-2022-42965Medium· 5.9
3y ago

snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)

snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)

Sunlitsnowflake-connector-python · snowflake-connector-pythonEPSS 0.86%via OSV
snowflake-connector-python vulnerabilities (CVEs) · VulnSea